Feature
Immediately update our org-wide GitHub Actions default policy configurations to the following:
Background
Recent software supply chain attacks have exposed critical weaknesses in GitHub Actions defaults. This proposes immediate, potentially breaking changes to how we manage GitHub Actions permissions.
I am proposing this change as part of the Shipwright community's response to the Trivy ecosystem compromise.
Feature
Immediately update our org-wide GitHub Actions default policy configurations to the following:
GITHUB_TOKENto be read-only forcontentsandpackages.Background
Recent software supply chain attacks have exposed critical weaknesses in GitHub Actions defaults. This proposes immediate, potentially breaking changes to how we manage GitHub Actions permissions.
I am proposing this change as part of the Shipwright community's response to the Trivy ecosystem compromise.