CodeCoverageSummary
CodeCoverageSummary copied to clipboard
Restrict token permissions for Auto Assign PR
Feature Request
The Auto Assign PR workflow doesn't have GitHub token permissions specified because it uses an Action not in the StepSecurity database.
Expected Behaviour
All workflows should restrict the GitHub token permissions.
Additional Context
- StepSecurity App
- samspills/assign-pr-to-author
Linked To
#49 Implement StepSecurity Secure Workflows (audit) #51 Implement StepSecurity Secure Workflows (policy)