Skip to content

A way to manage access around who can edit contents of .github/workflows/ #458

Open
@timharris777

Description

@timharris777

Enhancement: Provide role separation around who can edit contents of .github/workflows/

Reasoning: In an organization setting you have a lot of people who have write access to repositories. Add github actions workflows and secrets manager (think org level secret manager when it is released) and every person with write access could change a workflow file or create a new workflow file to print out the contents of a secret. Being able to limit the people who can edit workflows would be a huge plus in the security front.

@ds0440 @josephshanahan-cfa

Metadata

Metadata

Assignees

No one assigned

    Labels

    Service FeatureFeature scope to the pipelines service and launch app

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions