Skip to content

Restrict token permissions for Auto Assign PR #61

Description

@irongut

Feature Request

The Auto Assign PR workflow doesn't have GitHub token permissions specified because it uses an Action not in the StepSecurity database.

Expected Behaviour

All workflows should restrict the GitHub token permissions.

Additional Context

Linked To

#49 Implement StepSecurity Secure Workflows (audit)
#51 Implement StepSecurity Secure Workflows (policy)

Activity

  1. self-assigned this
    on Aug 5, 2022
  2. pinned this issue on Aug 5, 2022
  3. github-actions commented on Nov 4, 2022

    @github-actions

    This issue is stale because it has been open 90 days with no activity. Remove stale label or comment or this issue will be closed in 30 days.

  4. github-actions commented on Dec 5, 2022

    @github-actions

    This issue was closed because it has been stale for 30 days with no activity.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

DevOpsSecuritySecurity vulnerabilities or improvementsenhancementNew feature or requeststale

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions