adeo / mozaic-design-system

Mozaic Design System
https://mozaic.adeo.cloud
Apache License 2.0
68 stars 17 forks source link

ci(gha/workflows): release - update standard token permissions #1533

Closed tiloyi closed 5 months ago

tiloyi commented 5 months ago

I have read the contributing guidelines

Does this PR introduce a breaking change?

Describe the changes

Release Workflow - update standard token permissions

GitHub issue number or Jira issue URL: N/A

Other information

SimonCfn commented 5 months ago

Logo Checkmarx One – Scan Summary & Details34d68303-3e7b-408f-b59e-81e81159fe9a

New Issues

Severity Issue Source File / Package Checkmarx Insight
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 54 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 41 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 47 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 32 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 31
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 40
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 46
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 53