Skip to content

Set permissions for GitHub actions(chore:)#15793

Open
naveensrinivasan wants to merge 1 commit intoAlluxio:master-2.xfrom
turrisxyz:Pinned-Dependencies-GitHub
Open

Set permissions for GitHub actions(chore:)#15793
naveensrinivasan wants to merge 1 commit intoAlluxio:master-2.xfrom
turrisxyz:Pinned-Dependencies-GitHub

Conversation

@naveensrinivasan
Copy link
Copy Markdown

 Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much. - Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs [Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/) Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
@alluxio-bot
Copy link
Copy Markdown
Contributor

Automated checks report:

  • Commits associated with Github account: PASS
  • PR title follows the conventions: FAIL
    • The title of the PR does not pass all the checks. Please fix the following issues:
      • First word must be capitalized
      • First word of title ("chore:") is not an imperative verb. Please use one of the valid words

Some checks failed. Please fix the reported issues and reply 'alluxio-bot, check this please' to re-run checks.

@HelloHorizon HelloHorizon requested a review from Xenorith June 29, 2022 19:34
@Xenorith
Copy link
Copy Markdown
Contributor

thanks for surfacing this potential security issue. i've also changed the workflow permissions on the organizational level such that the GITHUB_TOKEN only has read permissions

@naveensrinivasan
Copy link
Copy Markdown
Author

thanks for surfacing this potential security issue. i've also changed the workflow permissions on the organizational level such that the GITHUB_TOKEN only has read permissions

👍

@HelloHorizon
Copy link
Copy Markdown
Contributor

@naveensrinivasan we need the CLA signed before we merge the code, do you mind sending me your email address to me(shouwei@alluxio.com) thus I can send you the CLA?

@naveensrinivasan
Copy link
Copy Markdown
Author

@naveensrinivasan we need the CLA signed before we merge the code, do you mind sending me your email address to me(shouwei@alluxio.com) thus I can send you the CLA?

Thanks, I will do it.

@naveensrinivasan
Copy link
Copy Markdown
Author

@naveensrinivasan we need the CLA signed before we merge the code, do you mind sending me your email address to me(shouwei@alluxio.com) thus I can send you the CLA?

Thanks, I will do it.

I have emailed it. Thanks

@HelloHorizon HelloHorizon changed the title chore: Set permissions for GitHub actions Set permissions for GitHub actions(chore:) Jul 11, 2022
@alluxio-bot
Copy link
Copy Markdown
Contributor

Automated checks report:

  • Commits associated with Github account: PASS
  • PR title follows the conventions: PASS

All checks passed!

@github-actions
Copy link
Copy Markdown

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed in two weeks if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale The PR/Issue does not have recent activities and will be closed automatically label Jan 31, 2023
@github-actions github-actions bot removed the stale The PR/Issue does not have recent activities and will be closed automatically label May 16, 2023
@github-actions
Copy link
Copy Markdown

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed in two weeks if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale The PR/Issue does not have recent activities and will be closed automatically label Jun 16, 2023
@github-actions github-actions bot removed the stale The PR/Issue does not have recent activities and will be closed automatically label Jun 25, 2024
@github-actions
Copy link
Copy Markdown

This pull request has been automatically marked as stale because it has not had recent activity. It will be closed in two weeks if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the stale The PR/Issue does not have recent activities and will be closed automatically label Jul 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-missing stale The PR/Issue does not have recent activities and will be closed automatically

4 participants