ad-m / ad-m/github-push-action

GITHUB_TOKEN permissions used by this action

未關閉
#111 3 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Shell
星號
1.3k
分支
238
PR 合併指標
30 天內沒有已合併 PR

描述

At https://github.com/step-security/secure-workflows we are building a knowledge-base (KB) of GITHUB_TOKEN permissions needed by different GitHub Actions. When developers try to set minimum token permissions for their workflows, they can use this knowledge-base instead of trying to research permissions needed by each GitHub Action they use.

Below you can see the KB of your GITHUB Action.
```yaml
name: 'GitHub Push'
github-token:
action-input:
input: github_token
is-default: true
permissions:
contents: write
contents-reason: to push local changes #Checkout: https://github.com/ad-m/github-push-action#github-action-for-github-push

#Fixes #496
```
If you think this information is not accurate, or if in the future your GitHub Action starts using a different set of permissions, please create an issue at https://github.com/step-security/secure-workflows/issues to let us know.

This issue is automatically created by our analysis bot, feel free to close after reading :)
### References:
GitHub asks users to define workflow permissions, see https://github.blog/changelog/2021-04-20-github-actions-control-permissions-for-github_token/ and https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token for securing GitHub workflows against supply-chain attacks.

Setting minimum token permissions is also checked for by Open Source Security Foundation (OpenSSF) [Scorecards](https://github.com/ossf/scorecard). Scorecards recommend using https://github.com/step-security/secure-workflows so developers can fix this issue in an easier manner.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。