-
Notifications
You must be signed in to change notification settings - Fork 20
Open
Milestone
Description
Feature
Immediately update our org-wide GitHub Actions default policy configurations to the following:
- Change the default permission of the
GITHUB_TOKENto be read-only forcontentsandpackages. - Require GitHub Actions workflows to be pinned by SHA.
- Require GitHub Actions to be explicitly approved for participants .
Background
Recent software supply chain attacks have exposed critical weaknesses in GitHub Actions defaults. This proposes immediate, potentially breaking changes to how we manage GitHub Actions permissions.
I am proposing this change as part of the Shipwright community's response to the Trivy ecosystem compromise.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
No status