Skip to content

Add GitHub token permissions for GitHub Actions workflow #54

@ceki

Description

@ceki

Related issue submitted to SLF4J/logback projects by @varunsh-coder Varun Sharma varunsh@stepsecurity.io

GitHub recommends defining minimum GITHUB_TOKEN permissions for securing GitHub Actions workflows.

See:
GitHub Actions: Control permissions for GITHUB_TOKEN
About the GITHUB_TOKEN secret

The Open Source Security Foundation (OpenSSF) Scorecards treats not setting token permissions as a high-risk issue

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions