Replies: 2 comments
This comment was marked as off-topic.
This comment was marked as off-topic.
-
|
A quick fix here could be to remove the |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Why are you starting this discussion?
Bug
What GitHub Actions topic or product is this about?
Workflow Configuration
Discussion Details
Please provide a repository role where users can approve PRs, but cannot write to/change secrets used in workflows.
This seems like a pretty huge security oversight that anybody with write access to the repo can change secret values.
Users with write permissions are still restricted by rulesets to prevent causing damage to the contents of a repo. Access to secrets should also be restricted.
The only way to implement such a requirement already would be to make use of a GitHub Enterprise subscription. At a cost of $20 per user/month, this is just not an option for open source projects that want to care about supply chain security.
Beta Was this translation helpful? Give feedback.
All reactions