Skip to content

Document OSS permission posture#44

Merged
Will-thom merged 1 commit into
mainfrom
security/oss-permission-audit
May 26, 2026
Merged

Document OSS permission posture#44
Will-thom merged 1 commit into
mainfrom
security/oss-permission-audit

Conversation

@Will-thom
Copy link
Copy Markdown
Collaborator

Summary

  • Document the repository permission posture for public OSS stabilization.
  • Record that public mode keeps branch protection available without a paid plan.
  • Reduce release workflow default token scope to read-only, with write access only on the publish job.

Validation

  • go test ./... with repository-local GOCACHE
  • GitHub API audit confirmed public visibility and main branch protection with All CI checks.

@github-actions
Copy link
Copy Markdown

Hi @Will-thom, thank you for contributing to PR Maven CLI.

I appreciate the time you spent opening this pull request. This project is intentionally shaped for focused, reviewable open source contributions, so your input helps the tool become more useful for Java and Maven teams.

A maintainer will review the context, labels, and next steps as soon as possible. If this is your first contribution here, welcome aboard.

Useful links:

  • Contributing guide: CONTRIBUTING.md
  • Testing guide: docs/testing.md
  • CI/CD guide: docs/ci.md

Thank you for helping build a deterministic, local-first Maven failure triage tool.

@Will-thom Will-thom merged commit c227047 into main May 26, 2026
21 checks passed
@Will-thom Will-thom deleted the security/oss-permission-audit branch May 26, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant