Skip to content

ci: add GitHub token permissions - #92999

Merged
ewdurbin merged 1 commit into
python:mainfrom
varunsh-coder:token-perms
May 21, 2022
Merged

ci: add GitHub token permissions#92999
ewdurbin merged 1 commit into
python:mainfrom
varunsh-coder:token-perms

Conversation

@varunsh-coder

Copy link
Copy Markdown
Contributor

GitHub asks developers to define workflow permissions, see https://github.blog/changelog/2021-04-20-github-actions-control-permissions-for-github_token/ and https://docs.github.com/en/actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token for securing GitHub workflows against supply-chain attacks.

The Open Source Security Foundation (OpenSSF) Scorecards also treats not setting token permissions as a high-risk issue.

This PR adds minimum token permissions for the GITHUB_TOKEN using https://github.com/step-security/secure-workflows.

This project is part of the top 100 critical projects as per OpenSSF (https://github.com/ossf/wg-securing-critical-projects), so fixing the token permissions to improve security.

@ghost

ghost commented May 20, 2022

Copy link
Copy Markdown

All commit authors signed the Contributor License Agreement.
CLA signed

@bedevere-bot

Copy link
Copy Markdown

Most changes to Python require a NEWS entry.

Please add it using the blurb_it web app or the blurb command-line tool.

@ewdurbin

Copy link
Copy Markdown
Member

Thank you @varunsh-coder

@ezio-melotti

Copy link
Copy Markdown
Member

@ewdurbin, any reason not to backport this PR to 3.11/3.10?

@ewdurbin

Copy link
Copy Markdown
Member

@ezio-melotti not that I'm aware of unless the workflows do not exist.

@ezio-melottiezio-melotti added needs backport to 3.10 only security fixes needs backport to 3.11 only security fixes labels Oct 10, 2022
@miss-islington

Copy link
Copy Markdown
Contributor

Thanks @varunsh-coder for the PR, and @ewdurbin for merging it 🌮🎉.. I'm working now to backport this PR to: 3.11.
🐍🍒⛏🤖

@miss-islington

Copy link
Copy Markdown
Contributor

Thanks @varunsh-coder for the PR, and @ewdurbin for merging it 🌮🎉.. I'm working now to backport this PR to: 3.10.
🐍🍒⛏🤖

miss-islington pushed a commit to miss-islington/cpython that referenced this pull request Oct 10, 2022
(cherry picked from commit b96e20c)
Co-authored-by: Varun Sharma <varunsh@stepsecurity.io>
@bedevere-botbedevere-bot removed the needs backport to 3.11 only security fixes label Oct 10, 2022
@miss-islington

Copy link
Copy Markdown
Contributor

Sorry, @varunsh-coder and @ewdurbin, I could not cleanly backport this to 3.10 due to a conflict.
Please backport using cherry_picker on command line.
cherry_picker b96e20c1d9be4e6d5ea3e48c9c97e5ecd02f6055 3.10

@bedevere-bot

Copy link
Copy Markdown

GH-98160 is a backport of this pull request to the 3.11 branch.

@bedevere-bot

Copy link
Copy Markdown

GH-98161 is a backport of this pull request to the 3.10 branch.

@bedevere-botbedevere-bot removed the needs backport to 3.10 only security fixes label Oct 10, 2022
miss-islington added a commit that referenced this pull request Oct 10, 2022
(cherry picked from commit b96e20c)
Co-authored-by: Varun Sharma <varunsh@stepsecurity.io>
ezio-melotti added a commit that referenced this pull request Oct 10, 2022
* ci: add GitHub token permissions (#92999)
(cherry picked from commit b96e20c)
* [3.10] ci: add GitHub token permissions (GH-92999).
(cherry picked from commit b96e20c)
Co-authored-by: Varun Sharma <varunsh@stepsecurity.io>
Co-authored-by: Varun Sharma <varunsh@stepsecurity.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@varunsh-coder@bedevere-bot@ewdurbin@ezio-melotti@miss-islington@erlend-aasland