MarkBind / markbind

MarkBind is a tool for generating content-heavy websites from source files in Markdown format
https://markbind.org/
MIT License
134 stars 123 forks source link

Add documentation regarding security practices for github actions #2528

Closed KevinEyo1 closed 2 months ago

KevinEyo1 commented 2 months ago

What is the purpose of this pull request?

Overview of changes: Resolves #2515

2488

Anything you'd like to highlight/discuss: Only included the research of practices currently being used, so things like version tagging is not documented.

Testing instructions:

Proposed commit message: (wrap lines at 72 characters) When writing GitHub action workflows, developers might miss out on security conventions.

Let's document current security practices in our developer guide so that future developers can follow these conventions.


Checklist: :ballot_box_with_check:


Reviewer checklist:

Indicate the SEMVER impact of the PR:

At the end of the review, please label the PR with the appropriate label: r.Major, r.Minor, r.Patch.

Breaking change release note preparation (if applicable):

Give a brief explanation note about:

  • what was the old feature that was made obsolete
  • any replacement feature (if any), and
  • how the author should modify his website to migrate from the old feature to the replacement feature (if possible).
github-actions[bot] commented 2 months ago

@KevinEyo1 Each PR must have a SEMVER impact label, please remember to label the PR properly.