Skip to content

Reducing security risk in our GitHub workflows #11

@afshin

Description

@afshin

We have switched the default behavior for this org to "Workflows have read permissions in the repository for the contents scope only" to utilize GitHub Actions: Control permissions for GITHUB_TOKEN .  See also jupyterhub/team-compass#404

An example PR that allows fine-grained permissions is jupyterlab/jupyterlab#10136.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions