Skip to content

[FEATURE]: Lock Down GitHub Actions #300

@adambkaplan

Description

@adambkaplan

Feature

Immediately update our org-wide GitHub Actions default policy configurations to the following:

Background

Recent software supply chain attacks have exposed critical weaknesses in GitHub Actions defaults. This proposes immediate, potentially breaking changes to how we manage GitHub Actions permissions.

I am proposing this change as part of the Shipwright community's response to the Trivy ecosystem compromise.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    Status

    No status

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions