You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm here to suggest that you set minimal permissions to your workflow pr_review_trigget.yml, because currently it doesn't specify the permissions for its jobs and their privileges are being determined by GitHub's defaults. I noticed that all of your other workflows already have the permissions defined, so I'll assume you already know the security benefits involved =)
If you have a reason not to define the permissions on that specific workflow, let me know! Otherwise I'll already raise a PR to add them and close this issue, as it's a very simple change.
Context
I'm Diogo and I work on Google's Open Source Security Team(GOSST) in cooperation with the Open Source Security Foundation (OpenSSF). My core job is to suggest and implement security changes on widely used open source projects 😊
Component(s)
Continuous Integration
The text was updated successfully, but these errors were encountered:
Describe the enhancement requested
Hi!
I'm here to suggest that you set minimal permissions to your workflow pr_review_trigget.yml, because currently it doesn't specify the permissions for its jobs and their privileges are being determined by GitHub's defaults. I noticed that all of your other workflows already have the permissions defined, so I'll assume you already know the security benefits involved =)
If you have a reason not to define the permissions on that specific workflow, let me know! Otherwise I'll already raise a PR to add them and close this issue, as it's a very simple change.
Context
I'm Diogo and I work on Google's Open Source Security Team(GOSST) in cooperation with the Open Source Security Foundation (OpenSSF). My core job is to suggest and implement security changes on widely used open source projects 😊
Component(s)
Continuous Integration
The text was updated successfully, but these errors were encountered: