Skip to content

Conversation

@maxday
Copy link
Member

@maxday maxday commented May 28, 2025

Follow-up of those PRs : #1824 and #1823

This PRs will bump our score from 0 to 10 for the Token-Permissions part.

I've merged this commit on my fork to see that it indeed fix all the security issues detected by OSSF.
Screenshot 2025-05-28 at 12 44 17 PM
(source: https://scorecard.dev/viewer/?uri=github.com/maxday/opentelemetry-lambda where this commit has been merged to my main branch)

This is important because we now are restricting the write permission at the job level (as recommended here: https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#token-permissions)

@maxday maxday requested a review from a team as a code owner May 28, 2025 11:48
@serkan-ozal serkan-ozal merged commit be01abc into open-telemetry:main May 31, 2025
11 checks passed
@tylerbenson tylerbenson added the github_actions Pull requests that update GitHub Actions code label Jun 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants