Skip to content

Restrict GITHUB_TOKEN in markdownlint action - #61622

Merged
safern merged 1 commit into
dotnet:mainfrom
vcsjones:markdownlint-restrict
Nov 15, 2021
Merged

Restrict GITHUB_TOKEN in markdownlint action#61622
safern merged 1 commit into
dotnet:mainfrom
vcsjones:markdownlint-restrict

Conversation

@vcsjones

@vcsjonesvcsjones commented Nov 15, 2021

Copy link
Copy Markdown
Member

The markdownlint workflow can be restricted from all access except the repository contents. This limits what the 3rd party markdownlint-cli npm package can do which is installed as part of the workflow.

Currently, Actions in the dotnet/runtime repository have read/write
access by default, unless their permissions have been explicitly declared.
The markdownlint workflow can be restricted from all access except the
repository contents. This limits what the 3rd party `markdownlint-cli`
npm package can do which is installed as part of the workflow.
@ghost

Copy link
Copy Markdown

I couldn't figure out the best area label to add to this PR. If you have write-permissions please help me learn by adding exactly one area label.

@ghostghost added the community-contribution Indicates that the PR has been added by a community member label Nov 15, 2021
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/runtime-infrastructure
See info in area-owners.md if you want to be subscribed.

Issue Details

The markdownlint workflow can be restricted from all access except the repository contents. This limits what the 3rd party markdownlint-cli npm package can do which is installed as part of the workflow.

Author:vcsjones
Assignees:-
Labels:

area-Infrastructure, community-contribution

Milestone:-

@safernsafern left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@vcsjones

Copy link
Copy Markdown
MemberAuthor

I tested this in a separate repository with the same workflow files, so, I think this is good to merge.

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Infrastructurecommunity-contributionIndicates that the PR has been added by a community member

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@vcsjones@mmitche@hoyosjs@safern