Skip to content

Commit 6a48f72

Browse files
author
Mark R. Tuttle
committed
Restrict OIDC role assumption to debugger-* tag
1 parent d7def9d commit 6a48f72

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

.github/cloudformation/token.yaml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,10 @@ Parameters:
1313
Type: String
1414
Description: GitHub repository for the cbmc-proof-debugger
1515
Default: cbmc-proof-debugger
16+
PublicationTag:
17+
Type: String
18+
Description: GitHub tag triggering the GitHub publication workflow
19+
Default: debugger-*
1620

1721
Resources:
1822

@@ -44,7 +48,7 @@ Resources:
4448
token.actions.githubusercontent.com:aud: sts.amazonaws.com
4549
StringLike:
4650
token.actions.githubusercontent.com:sub:
47-
!Sub repo:${GithubRepoOrganization}/${GithubRepoName}:*
51+
!Sub repo:${GithubRepoOrganization}/${GithubRepoName}:refref:refs/tags/${PublicationTag}
4852

4953
Policies:
5054
- PolicyName: PublisherTokenAccess

0 commit comments

Comments
 (0)