sashashura opened a new pull request, #549:
URL: https://github.com/apache/tomcat/pull/549

   This PR adds explicit [permissions 
section](https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions)
 to workflows. This is a security best practice because by default workflows 
run with [extended set of 
permissions](https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token)
 (except from `on: pull_request` [from external 
forks](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)).
 By specifying any permission explicitly all others are set to none. By using 
the principle of least privilege the damage a compromised workflow can do 
(because of an 
[injection](https://securitylab.github.com/research/github-actions-untrusted-input/)
 or compromised third party tool or action) is restricted.
   It is recommended to have [most strict permissions on the top 
level](https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions)
 and grant write permissions on [job 
level](https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs)
 case by case.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to