Skip to content

Restrict token permissions for Auto Assign PR #61

@irongut

Description

@irongut

Feature Request

The Auto Assign PR workflow doesn't have GitHub token permissions specified because it uses an Action not in the StepSecurity database.

Expected Behaviour

All workflows should restrict the GitHub token permissions.

Additional Context

Linked To

#49 Implement StepSecurity Secure Workflows (audit)
#51 Implement StepSecurity Secure Workflows (policy)

Metadata

Metadata

Assignees

Labels

DevOpsSecuritySecurity vulnerabilities or improvementsenhancementNew feature or requeststale

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions