Skip to content

Conversation

@nathannaveen
Copy link
Contributor

 Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

Signed-off-by: nathannaveen <[email protected]>
@nathannaveen nathannaveen requested a review from HLeithner as a code owner June 26, 2022 01:00
@HLeithner HLeithner merged commit 7937482 into joomla:4.2-dev Jun 27, 2022
@HLeithner
Copy link
Member

Thanks

@richard67 richard67 added the Maintainers Checked Used if the PR is conceptional useful label Jun 27, 2022
@richard67
Copy link
Member

I've reviewed the PR and the linked docs, too, and approve the changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Maintainers Checked Used if the PR is conceptional useful

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants