Skip to content

Actions should be locked down and only request desired permissions #41

@ThorstenHans

Description

@ThorstenHans

Our Actions currently need

  • access to the content
  • write access for issues (they create issues if container image does not align with CIS benchmark according to dockle)
  • secret access (read)
  • secret access write (used only by those actions that create passwords in azure after infra deployment)

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions