You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Because the 3rd party hooks have already run at least once, and the likelihood of exploitation is low. This Issue is a long term improvement on our CI pipeline, and not a blocker for the releases.
@l0r3bo can you provide more details on how to solve this issue? Thank you in advance.
The text was updated successfully, but these errors were encountered:
Right now, any of the GH actions are using the default permissions, which are quite permissive.
Any of the GH Action runs shows these permissions during
Set up job
phase.Here is the documentation to modify the GITHUB_TOKEN permissions. We may need to experiment on the GH Actions on what kind of permission they may need so that we can remove the unnecessary ones.
Because the 3rd party hooks have already run at least once, and the likelihood of exploitation is low. This Issue is a long term improvement on our CI pipeline, and not a blocker for the releases.
@l0r3bo can you provide more details on how to solve this issue? Thank you in advance.
The text was updated successfully, but these errors were encountered: