Skip to content

Restrict workflow token permissions #4673

@vicentebolea

Description

@vicentebolea

GitHub Actions workflows are using tokens with excessive permissions. Should explicitly set minimal permissions using the permissions: key in each workflow.

Most workflows should be read-only unless they specifically need write access.

Reference: https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions