Skip to content

Comments

docs: add security recommendations for SHA pinning and permissions#172

Open
chad-loder wants to merge 1 commit intofreckle:mainfrom
chad-loder:security-docs
Open

docs: add security recommendations for SHA pinning and permissions#172
chad-loder wants to merge 1 commit intofreckle:mainfrom
chad-loder:security-docs

Conversation

@chad-loder
Copy link

This PR adds a new 'Security Recommendations' section to the README that covers two important security best practices: 1) SHA Pinning - Using full commit SHAs instead of version tags to protect against supply chain attacks; 2) Minimal Permissions - Restricting workflow permissions to only what's necessary.

@chad-loder chad-loder requested a review from a team as a code owner March 20, 2025 11:42
@chad-loder chad-loder requested review from z0isch and removed request for a team March 20, 2025 11:42
@z0isch z0isch requested review from a team and joris974 and removed request for a team and z0isch March 20, 2025 13:42
Restrict the workflow permissions to only what is needed:

```yaml
permissions:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great call. Please feel free to include these permissions restrictions in the template in the Usage section of this README. Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants