Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Github Token Security via https://app.stepsecurity.io/securerepo tool #116

Closed
wants to merge 2 commits into from

Conversation

Perni1984
Copy link

@Perni1984 Perni1984 commented Dec 18, 2024

This PR:

I used the tool at https://app.stepsecurity.io/securerepo to improve the github token security of the github workflows. Reason is, we would like to use the package in one of our projects, but we need to have at least a 5 / 10 score on OSS Scorecards check.

With this change you receive 10/10 on the Token Permission Check instead of 0/10 that you score now.

With this change we would jump over the 5 / 10 overall score.

Unfortunately I don't know how to make a changeset. Kindly explain it to me, if I should add something else.

  • [] (if ready to be merged) Yes I have made a changeset

step-security-bot and others added 2 commits December 18, 2024 16:40
…_1734540038

[StepSecurity] Apply security best practices
@ethanniser ethanniser closed this Feb 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants