Automation to enforce repository permissions are by github team only and not individuals
- Dominant language
- No language data
- Stars
- 749
- Forks
- 72
- PR merge metrics
- No merged PRs in 30d
Description
### Is your feature request related to a problem?
To ensure that permissions are easier to maintain and keep updated, its a best practice to give permission to a GitHub team and then instead of removing them from a large number of repos, you can just remove them from the team. Well maintained permissions improves security posture.
The task here would be to create a/utilize an existing GitHub action or App to accomplish this.
Contributor guide
Research direction
No files or tests are identified. Start by comparing a GitHub Action with a GitHub App for enforcing team-only repository permissions, then define how existing individual permissions are handled and what repositories are in scope. Done means the chosen automation enforces or reports violations and its expected behavior is documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, github-actions
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100