googleapis / googleapis/google-http-java-client

Set minimum permissions for workflows

Offen
#1,900 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
type: feature request
Vorherrschende Sprache
Java
Sterne
1.4k
Forks
473
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Thanks for stopping by to let us know something could be better!

**PLEASE READ**: If you have a support contract with Google, please create an issue in the [support console](https://cloud.google.com/support/) instead of filing on GitHub. This will ensure a timely response.

**Is your feature request related to a problem? Please describe.**
GitHub workflows are [granted high permissions by default](https://docs.github.com/en/actions/security-guides/automatic-token-authentication). Permissions that allow, for example, to delete your source code and publish releases. The permissions can be exploited by malicious actions run in the workflow or malicious PRs if run on `pull_request_target`. This is specially important when using 3P actions such as:
https://github.com/googleapis/google-http-java-client/blob/1acedf75368f11ab03e5f84dd2c58a8a8a662d41/.github/workflows/ci-java7.yaml#L42.

**Describe the solution you'd like**
[Set restricted permissions to run GitHub workflows](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-the-default-github_token-permissions) or [declare minimum permissions in the workflows](https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs).
e.g. `permissions: contents: read` for workflows that only need to do `actions/checkout`.

**Describe alternatives you've considered**
None.

**Additional context**
My name is Gabriela and I work on behalf of Google and the OpenSSF suggesting supply-chain security changes.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.