We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 10f3406 commit 1524716Copy full SHA for 1524716
.github/workflows/wf3.yml
@@ -0,0 +1,26 @@
1
+name: Test GitHubToken Excessive Permissions
2
+on:
3
+ push:
4
+ branches:
5
+ - main
6
+jobs:
7
+ test-permissions:
8
+ runs-on: ubuntu-latest
9
+ # Overly broad permissions for GITHUB_TOKEN
10
+ permissions:
11
+ contents: write
12
+ issues: write
13
+ pull-requests: write
14
+ actions: write
15
+ checks: write
16
+ deployments: write
17
+ statuses: write
18
+ packages: write
19
+ repository-projects: write
20
+ discussions: write
21
+ security-events: write # This one, in particular, should raise a flag as it's typically not needed for most workflows
22
+ steps:
23
+ - name: Checkout code
24
+ uses: actions/checkout@v3
25
+ - name: Dummy Step
26
+ run: echo "This is to test excessive token permissions"
0 commit comments