[github action] Follow the principle of least privileges#7673
Merged
Pierre-Sassoulas merged 1 commit intopylint-dev:mainfrom Oct 26, 2022
Merged
Conversation
Pull Request Test Coverage Report for Build 3323819181
💛 - Coveralls |
This comment has been minimized.
This comment has been minimized.
ba1cd22 to
6b89f53
Compare
Member
Author
Contributor
cdce8p
approved these changes
Oct 26, 2022
Member
cdce8p
left a comment
There was a problem hiding this comment.
Looks good, but I don't think it's necessary anymore.
The same can be archived by modifying the Action permissions -> Workflow permissions in the repo settings. I just toggled Read repository contents permission, so contents: read is the default for all workflows.
--
FYI I also modified a few other Action permissions settings to increase security.
- Disabled
Allow Github Actions to create and approve pull requests - Only allow specific / predefined actions and reusable workflows.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Type of Changes
Description
This set the least amount of privilege for each github actions when it wasn't already set.
Full disclosure, I'm being paid to make pylint more secure by Tidelift and this is part of this effort.