Skip to content

Security Hardening for GitHub Actions workflows #1842

Closed
@jpower432

Description

@jpower432

Issue description / feature objectives

Review and apply security fixes to GitHub Actions Workflows. The scorecard remediation action documents an option to fix multiple issues at one time by visiting https://app.stepsecurity.io/secureworkflow.

Completion Criteria

  • Scorecard: Pin third-party actions to a full length commit SHA
  • Scorecard: Set top-level permissions for GITHUB_TOKEN

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions