Skip to content

fix: token permissions #1836

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
May 31, 2025
Merged

Conversation

maxday
Copy link
Member

@maxday maxday commented May 28, 2025

Follow-up of those PRs : #1824 and #1823

This PRs will bump our score from 0 to 10 for the Token-Permissions part.

I've merged this commit on my fork to see that it indeed fix all the security issues detected by OSSF.
Screenshot 2025-05-28 at 12 44 17 PM
(source: https://scorecard.dev/viewer/?uri=github.com/maxday/opentelemetry-lambda where this commit has been merged to my main branch)

This is important because we now are restricting the write permission at the job level (as recommended here: https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#token-permissions)

@maxday maxday requested a review from a team as a code owner May 28, 2025 11:48
@serkan-ozal serkan-ozal merged commit be01abc into open-telemetry:main May 31, 2025
11 checks passed
@tylerbenson tylerbenson added the github_actions Pull requests that update GitHub Actions code label Jun 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants