Skip to content

Actions should be locked down and only request desired permissions #41

@ThorstenHans

Description

@ThorstenHans

Our Actions currently need

  • access to the content
  • write access for issues (they create issues if container image does not align with CIS benchmark according to dockle)
  • secret access (read)
  • secret access write (used only by those actions that create passwords in azure after infra deployment)

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions