secure-repo icon indicating copy to clipboard operation
secure-repo copied to clipboard

[KB] Add GitHub token permissions for google-github-actions/get-gke-credentials Action

Open step-security-bot opened this issue 3 years ago • 1 comments

Knowledge Base is missing for google-github-actions/get-gke-credentials.

step-security-bot avatar Oct 02 '22 11:10 step-security-bot

Analysis

Action Name: google-github-actions/get-gke-credentials
Action Type: Node
GITHUB_TOKEN Matches: token
Top language: TypeScript
Stars: 51
Private: false
Forks: 30

Endpoints Found

Endpoint Permission

FollowUp Links.

https://github.com/google-github-actions/get-gke-credentials/blob/f75ef7d6da6a1620afab3996356e5ff8485a4e94/tests/clusterClient.test.ts https://github.com/google-github-actions/get-gke-credentials/blob/f75ef7d6da6a1620afab3996356e5ff8485a4e94/src/gkeClient.ts

action-security.yml

name: Get GKE Credentials
github-token:
  environment-variable-name: <FigureOutYourself>
    is-default: false
  permissions:

step-security-bot avatar Oct 02 '22 11:10 step-security-bot