infinispan / infinispan/cpp-client

Harden GitHub Actions with top-level permissions and SHA pinning

Open
#422 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
11
Forks
20
PR merge metrics
No merged PRs in 30d

Description

Add explicit top-level permissions blocks to all workflow files, defaulting to contents: read with elevated scopes only where needed. Pin every external action reference to immutable 40-char commit SHAs with trailing version comments, preventing supply-chain attacks via mutable tag/branch references.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Inspect all GitHub Actions workflow files and inventory their top-level permissions and external action references. Compare each workflow with the requested contents: read default, least-privilege elevated scopes, immutable 40-character SHAs, and trailing version comments; done means every workflow follows these rules and CI configuration remains valid.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.