Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Policy violation Outside Collaborators #1513

Open
google-allstar-prod bot opened this issue Mar 17, 2024 · 3 comments
Open

Security Policy violation Outside Collaborators #1513

google-allstar-prod bot opened this issue Mar 17, 2024 · 3 comments
Assignees
Labels
internal-issue-created Google internal issue has been created for this org policy violation triage-done

Comments

@google-allstar-prod
Copy link

This issue was automatically created by Allstar.

Security Policy Violation
Found 4 outside collaborators with push access.
This policy requires users with this access to be members of the organisation. That way you can easily audit who has access to your repo, and if an account is compromised it can quickly be denied access to organization resources. To fix this you should either remove the user from repository-based access, or add them to the organization.

OR

If you don't see the Settings tab you probably don't have administrative access. Reach out to the administrators of the organisation to fix this issue.

OR

  • Exempt the user by adding an exemption to your organization-level Outside Collaborators configuration file.

This issue will auto resolve when the policy is in compliance.

Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.

@lvelden
Copy link

lvelden commented Mar 18, 2024

Created Google internal issue http://b/330118133.

@lvelden lvelden added internal-issue-created Google internal issue has been created for this triage-done labels Mar 18, 2024
@lvelden
Copy link

lvelden commented Mar 19, 2024

I believe this should be fixed, but "This issue will auto resolve when the policy is in compliance" didn't happen yet. Is there still something not compliant?

@devversion
Copy link
Member

@lvelden there are no outside collaborators for this repository. I was also hoping this would auto-resolve, but it may just take some time— not sure how often org Allstar runs here. Let's keep it open to see

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
internal-issue-created Google internal issue has been created for this org policy violation triage-done
Projects
None yet
Development

No branches or pull requests

2 participants