Details
-
Improvement
-
Resolution: Fixed
-
Major
-
None
-
None
-
None
Description
This work has been done as part of PR: https://github.com/qos-ch/logback/pull/579
GitHub recommends defining minimum GITHUB_TOKEN permissions for securing GitHub Actions workflows
- https://github.blog/changelog/2021-04-20-github-actions-control-permissions-for-github_token/
- https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token
- The Open Source Security Foundation (OpenSSF) Scorecards treats not setting token permissions as a high-risk issue
Attachments
Issue Links
- links to