allstar icon indicating copy to clipboard operation
allstar copied to clipboard

Policy Idea: Default workflow permissions.

Open jeffmendoza opened this issue 3 years ago • 1 comments

GitHub has two defaults for permissions of Actions workflows (if the workflow yaml does not specify permissions) Screenshot 2022-08-24 11 51 50 AM Details here see the "permissive" and "restricted" column.

Looks like this is settable at the org level already: https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token Not sure what an Allstar policy would look like, need to dig in further.

jeffmendoza avatar Aug 24 '22 19:08 jeffmendoza