Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

.github: workflows: restrict top-level workflow permissions #3140

Merged
merged 1 commit into from
Sep 19, 2024

Conversation

pcolberg
Copy link
Contributor

Only permit reading the repository contents by default, and set further privileges at the job level to satisfy OpenSSF Scorecard criteria.

Link: https://github.com/ossf/scorecard/blob/9ff40de429d0c7710076070387c8755494a9f187/docs/checks.md#token-permissions
Link: https://securityscorecards.dev/viewer/?uri=github.com/OFS/opae-sdk

Only permit reading the repository contents by default, and set further
privileges at the job level to satisfy OpenSSF Scorecard criteria.

Link: https://github.com/ossf/scorecard/blob/9ff40de429d0c7710076070387c8755494a9f187/docs/checks.md#token-permissions
Link: https://securityscorecards.dev/viewer/?uri=github.com/OFS/opae-sdk
Signed-off-by: Peter Colberg <[email protected]>
@pcolberg pcolberg requested a review from fpgamatt September 18, 2024 21:47
@pcolberg pcolberg self-assigned this Sep 18, 2024
@pcolberg pcolberg requested a review from a team as a code owner September 18, 2024 21:47
@coveralls
Copy link

Pull Request Test Coverage Report for Build 10930627940

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 64.245%

Totals Coverage Status
Change from base Build 10458274117: 0.0%
Covered Lines: 15826
Relevant Lines: 24634

💛 - Coveralls

@pcolberg pcolberg merged commit 6d971f4 into master Sep 19, 2024
35 checks passed
@pcolberg pcolberg deleted the pcolberg/openssf branch September 19, 2024 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

3 participants