Set github workflow to minimal permissions · Issue #438 · python/importlib

您所在的位置:网站首页 python importlib reload Set github workflow to minimal permissions · Issue #438 · python/importlib

Set github workflow to minimal permissions · Issue #438 · python/importlib

2023-03-17 12:48| 来源: 网络整理| 查看: 265

@joycebrum thank you for opening this issue, it is very appreciated!

We do have CI configured to only run automatically for previous contributors, which should mitigate a significant portion of such attacks, but there's indeed no reason to have these permissions enabled. It's actually surprising that this is the default.

Currently, we only have one job that needs such permissions, the release one, but it uses an external GITHUB_TOKEN, which I am assuming only has release upload permissions, but @jaraco could confirm.

I think with the implicit (probably not the best word 😅) GITHUB_TOKEN token, we don't actually need to specify a GITHUB_TOKEN, but I don't see any configuration key in the documentation you linked that is obvious to me to target releases.

Also, given that we do have a GITHUB_TOKEN secret already, do you know if it shadows the implicit one, or overwrites it? If that's the case, then we just need to make sure the token has the correct permissions, but it doesn't hurt to set the permissions settings anyway for future-proofing.



【本文地址】


今日新闻


推荐新闻


CopyRight 2018-2019 办公设备维修网 版权所有 豫ICP备15022753号-3