Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Harden GitHub Actions workflows #151

Merged
merged 1 commit into from
Dec 12, 2024
Merged

Harden GitHub Actions workflows #151

merged 1 commit into from
Dec 12, 2024

Conversation

ericcornelissen
Copy link
Collaborator

Summary

Update all GitHub Actions workflows following an analysis by zizmor. In particular, this avoids persisting git credentials when the job does not need it (which I believe is all but one job, which is a job that makes commits).

Update all GitHub Actions workflows following an analysis by `zizmor`
(https://github.com/woodruffw/zizmor). In particular, this avoids
persisting git credentials when the job does not need it (which I
believe is all but one job, which is a job that makes commits).

`zizmor` did have one more concern - overly permissive `read-all`
permissions - but this was not addressed because I think this is
okay, the project is entirely open so I don't see a risk of an
adversary reading anything.
@ericcornelissen ericcornelissen added ci/cd Relates to ci/cd security Relates to security labels Dec 9, 2024
@ericcornelissen ericcornelissen merged commit 8b39a15 into main Dec 12, 2024
11 checks passed
@ericcornelissen ericcornelissen deleted the harden-ghaw branch December 12, 2024 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci/cd Relates to ci/cd security Relates to security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant