csaf-tools / CVRF-CSAF-Converter

A CVRF CSAF Converter, taking care about OASIS specification.
https://www.telekom.com/security
MIT License
10 stars 4 forks source link

Update GHActions #117

Open tschmidtb51 opened 1 month ago

tschmidtb51 commented 1 month ago

We need to update the GHActions. actions/upload-artifact should be replaced by https://github.com/PaloAltoNetworks/upload-secure-artifact (See https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/). Also, use least privileges (see https://www.paloaltonetworks.com/blog/prisma-cloud/github-actions-opt-out-permissions-model/) in all actions.