diogoteles08 opened a new issue, #35706:
URL: https://github.com/apache/arrow/issues/35706

   ### Describe the enhancement requested
   
   Hi!
   
   I'm here to suggest that you set minimal permissions to your workflow 
[pr_review_trigget.yml](https://github.com/apache/arrow/blob/main/.github/workflows/pr_review_trigger.yml),
 because currently it doesn't specify the permissions for its jobs and their 
privileges are being determined by GitHub's defaults. I noticed that all of 
your other workflows already have the permissions defined, so I'll assume you 
already know the security benefits involved =)
   
   If you have a reason not to define the permissions on that specific 
workflow, let me know! Otherwise I'll already raise a PR to add them and close 
this issue, as it's a very simple change.
   
   #### Context
   I'm Diogo and I work on Google's Open Source Security 
Team([GOSST](https://github.com/diogoteles08#about-gosst-ghost)) in cooperation 
with the Open Source Security Foundation ([OpenSSF](https://openssf.org/)). My 
core job is to suggest and implement security changes on widely used open 
source projects 😊
   
   ### Component(s)
   
   Continuous Integration


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to