Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: Updating CI to use specific tagged versions of github actions and minimizing/enforcing permissions for all actions. #69

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

sdelliot
Copy link
Collaborator

This set of changes should enable a more secure CI pipeline (e.g., avoiding supply chain attacks) while still maintaining the current functionality. I suspect that the pipeline will still fail prior to merge due to some of the restrictions. Any issues after that can be addressed quickly.

@sdelliot sdelliot added ci Changes to our CI configuration files and scripts security Changes that impact security of the system labels Feb 21, 2025
@sdelliot sdelliot requested a review from mitchnegus February 21, 2025 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci Changes to our CI configuration files and scripts security Changes that impact security of the system
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant