? Pending

User tests: Successful: Unsuccessful:

avatar nathannaveen
nathannaveen
26 Jun 2022

Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests

Signed-off-by: nathannaveen 42319948+nathannaveen@users.noreply.github.com

avatar nathannaveen nathannaveen - open - 26 Jun 2022
avatar nathannaveen nathannaveen - change - 26 Jun 2022
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 26 Jun 2022
Category Repository
avatar HLeithner HLeithner - close - 27 Jun 2022
avatar HLeithner HLeithner - merge - 27 Jun 2022
avatar HLeithner HLeithner - change - 27 Jun 2022
Status Pending Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2022-06-27 13:01:06
Closed_By HLeithner
Labels Added: ?
avatar HLeithner
HLeithner - comment - 27 Jun 2022

Thanks

avatar richard67
richard67 - comment - 27 Jun 2022

I've reviewed the PR and the linked docs, too, and approve the changes.

Add a Comment

Login with GitHub to post a comment