Update workflow example in the README #25
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This patch makes the following changes to the example workflow in the
README.md
:actions/checkout
action tov2
instead ofmaster
persist-credentials: false
as a good practice so that the$GITHUB_TOKEN
is not made available to any action unless explicitly configured (checkout will sneakily write the token to disk where any step can pick it up)permissions
section to limit the scope of the$GITHUB_TOKEN
to just be able to read the repo contents and add security events.Assuming many folks copy/paste the example workflow from the
README.md
, I think these are good security changes to encourage.