github / github/github-ospo

Automation to enforce repository permissions are by github team only and not individuals

未关闭
#86 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement new-action
主要语言
没有语言数据
星标
749
派生
72
PR 合并指标
30 天内没有已合并 PR

描述

### Is your feature request related to a problem?

To ensure that permissions are easier to maintain and keep updated, its a best practice to give permission to a GitHub team and then instead of removing them from a large number of repos, you can just remove them from the team. Well maintained permissions improves security posture.

The task here would be to create a/utilize an existing GitHub action or App to accomplish this.

贡献指南

打开贡献指南

调研方向

未确定任何文件或测试。首先比较 GitHub Action 和 GitHub App,以强制执行仅限团队的仓库权限,然后定义如何处理现有的个人权限,以及哪些仓库属于范围之内。完成的标准是:所选自动化能够强制执行规则或报告违规情况,并且其预期行为已有文档说明。

由索引模型根据 Issue 内容生成。

评估

技术栈
github, github-actions
领域
devops, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。