Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[1.1.2] Token Permissions - High warnings for SLSA generation #850

Open
dbaileychess opened this issue Sep 2, 2022 · 3 comments
Open

[1.1.2] Token Permissions - High warnings for SLSA generation #850

dbaileychess opened this issue Sep 2, 2022 · 3 comments
Labels
bug Something isn't working

Comments

@dbaileychess
Copy link

I'm using version 1.1.2 and continue to get Token Permission - High warnings on enabling write permissions for SLSA generation. There was a recent exemption made for SLSA, but it doesn't seem to be working.

@dbaileychess dbaileychess added the bug Something isn't working label Sep 2, 2022
@azeemshaikh38
Copy link
Contributor

@dbaileychess I suspect v1.1.2 release my not have the latest changes yet. You could consider using our v2 pre-release: https://github.com/ossf/scorecard-action/releases/tag/v2.0.0-alpha.2 to see if it fixes the issue. We'll be releasing the prod v2 in a week so fyi that the pre-release is stable.

@laurentsimon do you know when this exception was rolled out in Scorecard?

PS: moving this to the scorecard-action repo for better tracking.

@azeemshaikh38 azeemshaikh38 transferred this issue from ossf/scorecard Sep 2, 2022
@laurentsimon
Copy link
Contributor

Action v1.1.2 uses scorecard v4.3.1, which did not include the fix. I was mistaken. Updating to the latest v2.0.0 should fix the problem. Can you give it a try?

@azeemshaikh38
Copy link
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants