Skip to content

Limit permissions of who can execute version update script#784

Merged
gauravgahlot merged 1 commit intoproject-akri:mainfrom
kate-goldenring:fix-version-script-perms
Mar 2, 2026
Merged

Limit permissions of who can execute version update script#784
gauravgahlot merged 1 commit intoproject-akri:mainfrom
kate-goldenring:fix-version-script-perms

Conversation

@kate-goldenring
Copy link
Contributor

What this PR does / why we need it:

Special notes for your reviewer:

If applicable:

  • this PR has an associated PR with documentation in akri-docs
  • this PR contains unit tests
  • added code adheres to standard Rust formatting (cargo fmt)
  • code builds properly (cargo build)
  • code is free of common mistakes (cargo clippy)
  • all Akri tests succeed (cargo test)
  • inline documentation builds (cargo doc)
  • all commits pass the DCO bot check by being signed off -- see the failing DCO check for instructions on how to retroactively sign commits

- Limit permissions of who can execute version update script
- Always checkout version update script from main to prevent script injection

Signed-off-by: Kate Goldenring <kate.goldenring@fermyon.com>
@gauravgahlot gauravgahlot merged commit c9f835d into project-akri:main Mar 2, 2026
4 of 5 checks passed
@gauravgahlot
Copy link
Member

Thank you @kate-goldenring! 🙇🏼

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants