-
-
Notifications
You must be signed in to change notification settings - Fork 70
Closed
Labels
DevOpsSecuritySecurity vulnerabilities or improvementsSecurity vulnerabilities or improvementsenhancementNew feature or requestNew feature or requeststale
Description
Feature Request
The Auto Assign PR workflow doesn't have GitHub token permissions specified because it uses an Action not in the StepSecurity database.
Expected Behaviour
All workflows should restrict the GitHub token permissions.
Additional Context
- StepSecurity App
- samspills/assign-pr-to-author
Linked To
#49 Implement StepSecurity Secure Workflows (audit)
#51 Implement StepSecurity Secure Workflows (policy)
Metadata
Metadata
Assignees
Labels
DevOpsSecuritySecurity vulnerabilities or improvementsSecurity vulnerabilities or improvementsenhancementNew feature or requestNew feature or requeststale