Skip to content

Bug "Ensure top-level permissions are not set to write-all" #120

@wjohnston-sfdc

Description

@wjohnston-sfdc

Hi, I ran your code through checkov https://www.checkov.io/5.Policy%20Index/github_actions.html.

Command

/dist/checkov -d ./ --framework github_actions

Check: CKV2_GHA_1: "Ensure top-level permissions are not set to write-all"
        FAILED for resource: on(ci)
        File: /.github/workflows/ci.yml:43-44

Are you able to add permissions: read to .github/workflows/ci.yml:43-44

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions