Skip to content

Restrict aw roles#2101

Merged
qmuntal merged 1 commit into
microsoft/mainfrom
dev/qmuntal/awrest
Feb 4, 2026
Merged

Restrict aw roles#2101
qmuntal merged 1 commit into
microsoft/mainfrom
dev/qmuntal/awrest

Conversation

@qmuntal
Copy link
Copy Markdown
Member

@qmuntal qmuntal commented Feb 3, 2026

AW security best practices (link) says that roles: all should be used carefully:

By default, workflows restrict execution to users with admin, maintainer, or write permissions. Use roles: all carefully in public repositories.

We better follow this advice until we get more experience with AW. The practical effect is that PRs from external contributors won't trigger the patch consistency review workflow.

@qmuntal qmuntal requested a review from a team as a code owner February 3, 2026 20:24
@qmuntal qmuntal enabled auto-merge February 3, 2026 20:26
@dagood
Copy link
Copy Markdown
Member

dagood commented Feb 3, 2026

Does the lock yml need to be regenerated?

@qmuntal qmuntal merged commit 1fa8f37 into microsoft/main Feb 4, 2026
43 checks passed
@qmuntal qmuntal deleted the dev/qmuntal/awrest branch February 4, 2026 00:59
@qmuntal
Copy link
Copy Markdown
Member Author

qmuntal commented Feb 4, 2026

Yes it did: #2102

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants