Skip to content

CI: Harden GHA Config#63

Open
Dr. Phil Maffettone (maffettone) wants to merge 5 commits intoNSLS2:humblefrom
maffettone:harden-gha
Open

CI: Harden GHA Config#63
Dr. Phil Maffettone (maffettone) wants to merge 5 commits intoNSLS2:humblefrom
maffettone:harden-gha

Conversation

@maffettone
Copy link
Copy Markdown
Contributor

Closes #62

This adjusts the defaults per suggestions of zizmor to
reduce possible risks from giving GHA tasks more permissions
that required.
This eliminates the possibility of a tag being changed under
us.
Reduces risk of arbitrary code is run by attacker.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants