-
Notifications
You must be signed in to change notification settings - Fork 705
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Lock down GitHub Actions Security #1256
Comments
This was referenced Apr 26, 2021
See briansmith/untrusted#50 regarding TODOs; in general everything I wrote there applies to this repo too. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Over the weekend, I merged PR #1253 which minimizes the permissions of the GitHub token. I also changed the default permission of the GitHub token from read-write to read-only in the repository settings, but I don't think people can see this.
Now we still need to follow the (rest of the) guidance in https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions to lock down our CI/CD.
Further, we need to ensure that all the dependencies of ring have implemented that guidance.
Further, we need to extend our CI/CD to ensure that no new dependencies without such hardening are added as dependencies of ring.
The text was updated successfully, but these errors were encountered: