Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix code scanning alert - Token-Permissions: .github/workflows/pr-title.yml #631

Open
1 task
ianlewis opened this issue Jun 2, 2023 · 0 comments
Open
1 task
Labels
area:hardening Issue related to security hardening type:bug Something isn't working

Comments

@ianlewis
Copy link
Member

ianlewis commented Jun 2, 2023

.github/workflows/pr-title.yml:1:
score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Tracking issue for:

@ianlewis ianlewis changed the title Fix code scanning alert - Token-Permissions Fix code scanning alert - Token-Permissions: .github/workflows/pr-title.yml Jun 2, 2023
@ianlewis ianlewis added area:hardening Issue related to security hardening type:bug Something isn't working labels Jun 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area:hardening Issue related to security hardening type:bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant