github / github/github-ospo

Automation to enforce repository permissions are by github team only and not individuals

Open
#86 2 comments 0 reactions 0 assignees View on GitHub
enhancement new-action
Dominant language
No language data
Stars
749
Forks
72
PR merge metrics
No merged PRs in 30d

Description

### Is your feature request related to a problem?

To ensure that permissions are easier to maintain and keep updated, its a best practice to give permission to a GitHub team and then instead of removing them from a large number of repos, you can just remove them from the team. Well maintained permissions improves security posture.

The task here would be to create a/utilize an existing GitHub action or App to accomplish this.

Contributor guide

Open the contributing guide

Research direction

No files or tests are identified. Start by comparing a GitHub Action with a GitHub App for enforcing team-only repository permissions, then define how existing individual permissions are handled and what repositories are in scope. Done means the chosen automation enforces or reports violations and its expected behavior is documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, github-actions
Domain
devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.