Skip to content

Add token permissions for py-cli.yml#414

Open
arjundashrath wants to merge 1 commit intoenzoampil:masterfrom
arjundashrath:patch-1
Open

Add token permissions for py-cli.yml#414
arjundashrath wants to merge 1 commit intoenzoampil:masterfrom
arjundashrath:patch-1

Conversation

@arjundashrath
Copy link

@arjundashrath arjundashrath commented Mar 9, 2022

GitHub asks users to define workflow permissions, see https://github.blog/changelog/2021-04-20-github-actions-control-permissions-for-github_token/ and https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token for securing GitHub workflows against supply-chain attacks.

The Open Source Security Foundation (OpenSSF) Scorecards also treats not setting token permissions as a high-risk issue.

This repository has a Scorecards score of 5.1/10 with 10 being the most secure. The Token-Permissions category has a score of 0/10.

This file was fixed automatically using the open-source tool https://github.com/step-security/secure-workflows. If you like the changes and merge them, please consider starring the repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant