Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci(pr-agent): reduce the contents:write permission to read for security #9598

Merged
merged 2 commits into from
Dec 10, 2024

Conversation

xmfcx
Copy link
Contributor

@xmfcx xmfcx commented Dec 9, 2024

Description

Due to security vulnerabilities, we'll limit the contents: write permission to read only.

Related links

How was this PR tested?

Notes for reviewers

None.

Interface changes

None.

Effects on system behavior

None.

@xmfcx xmfcx requested a review from mitsudome-r December 9, 2024 13:07
@xmfcx xmfcx self-assigned this Dec 9, 2024
@github-actions github-actions bot added the type:ci Continuous Integration (CI) processes and testing. (auto-assigned) label Dec 9, 2024
Copy link

github-actions bot commented Dec 9, 2024

Thank you for contributing to the Autoware project!

🚧 If your pull request is in progress, switch it to draft mode.

Please ensure:

@xmfcx xmfcx changed the title ci(pr-agent): remove contents write permission due to security ci(pr-agent): reduce the contents:write permission to read for security Dec 9, 2024
@xmfcx xmfcx added the tag:run-build-and-test-differential Mark to enable build-and-test-differential workflow. (used-by-ci) label Dec 9, 2024
Signed-off-by: M. Fatih Cırıt <[email protected]>
@xmfcx xmfcx force-pushed the ci/pr-agent-security branch from 1e074c3 to 151c404 Compare December 9, 2024 13:28
@xmfcx
Copy link
Contributor Author

xmfcx commented Dec 10, 2024

This was reviewed by the person who discovered and warned us about the exploit ✅

@xmfcx xmfcx merged commit c0c70cc into main Dec 10, 2024
27 checks passed
@xmfcx xmfcx deleted the ci/pr-agent-security branch December 10, 2024 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
tag:run-build-and-test-differential Mark to enable build-and-test-differential workflow. (used-by-ci) type:ci Continuous Integration (CI) processes and testing. (auto-assigned)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant