Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(.github/workflows): stricter GitHub token default permission compliance #2849

Merged

Conversation

darccio
Copy link
Member

@darccio darccio commented Sep 9, 2024

What does this PR do?

Modifies GitHub Actions' workflows to set the most restrictive permissions required.

Reviewer's Checklist

  • Changed code has unit tests for its functionality at or near 100% coverage.
  • System-Tests covering this feature have been added and enabled with the va.b.c-dev version tag.
  • There is a benchmark for any new code, or changes to existing code.
  • If this interacts with the agent in a new way, a system test has been added.
  • Add an appropriate team label so this PR gets put in the right place for the release notes.
  • Non-trivial go.mod changes, e.g. adding new modules, are reviewed by @DataDog/dd-trace-go-guild.

Unsure? Have a question? Request a review!

@pr-commenter
Copy link

pr-commenter bot commented Sep 9, 2024

Benchmarks

Benchmark execution time: 2024-09-10 07:47:05

Comparing candidate commit ac793cf in PR branch dario.castane/VULN-8316/insecure-default-workflow-permissions with baseline commit c29e8fa in branch main.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 59 metrics, 0 unstable metrics.

@github-actions github-actions bot added the apm:ecosystem contrib/* related feature requests or bugs label Sep 9, 2024
@darccio darccio removed the apm:ecosystem contrib/* related feature requests or bugs label Sep 9, 2024
@github-actions github-actions bot added the apm:ecosystem contrib/* related feature requests or bugs label Sep 9, 2024
@darccio darccio marked this pull request as ready for review September 9, 2024 16:14
@darccio darccio requested a review from a team as a code owner September 9, 2024 16:14
@darccio darccio requested a review from a team as a code owner September 9, 2024 16:14
@darccio darccio merged commit 043dcd1 into main Sep 26, 2024
165 of 166 checks passed
@darccio darccio deleted the dario.castane/VULN-8316/insecure-default-workflow-permissions branch September 26, 2024 08:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
apm:ecosystem contrib/* related feature requests or bugs
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants