Skip to content

Conversation

@ste93cry
Copy link
Contributor

@ste93cry ste93cry commented Nov 5, 2023

When setting explicitly any permission for the GitHub Workflow, the others get automatically set to none. This is considered a best practice because it restricts the amount of damage that a compromised GitHub Workflow can do by applying the principle of least privilege.

@cleptric cleptric merged commit 7ab08fa into getsentry:master Nov 5, 2023
@ste93cry ste93cry deleted the harden-github-workflows branch November 5, 2023 22:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants