Commit 60b94c6
Add least-privilege permissions to triage workflow
Add explicit permissions: block (pull-requests: write, issues: write) to
constrain GITHUB_TOKEN scope on pull_request_target trigger.
Ref: https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>1 parent 82c0b4f commit 60b94c6
1 file changed
+4
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
13 | 17 | | |
14 | 18 | | |
15 | 19 | | |
| |||
0 commit comments