Skip to content

Conversation

@soumeh01
Copy link
Collaborator

@soumeh01 soumeh01 commented May 12, 2025

Addressing partially: #221

Fixes

  • Only read access is granted by default, ensuring that:
    • Workflows and actions cannot modify repositories, secrets, or other sensitive resources unless explicitly allowed
    • Limits the blast radius if a workflow is compromised
    • Prevents Accidental Writes

@soumeh01 soumeh01 force-pushed the fix-security-vuln branch from c7ac7f6 to f64c0b4 Compare May 12, 2025 09:44
@soumeh01 soumeh01 marked this pull request as ready for review May 12, 2025 09:47
@soumeh01 soumeh01 requested a review from JonatanAntoni May 12, 2025 09:47
@soumeh01 soumeh01 requested review from jreineckearm and removed request for JonatanAntoni May 12, 2025 11:47
@soumeh01 soumeh01 requested a review from jreineckearm May 12, 2025 13:12
@soumeh01 soumeh01 force-pushed the fix-security-vuln branch from 42f33e2 to e5bd148 Compare May 12, 2025 18:00
Copy link
Collaborator

@jreineckearm jreineckearm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems to be working again. Good to merge.

@jreineckearm jreineckearm merged commit e7561c0 into main May 12, 2025
13 checks passed
@jreineckearm jreineckearm deleted the fix-security-vuln branch May 12, 2025 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants