github / docs

The open-source repo for docs.github.com
https://docs.github.com
Creative Commons Attribution 4.0 International
16.33k stars 59.84k forks source link

Add reference to OSSF Scorecards in the GitHub Actions hardening guide #14855

Closed varunsh-coder closed 2 years ago

varunsh-coder commented 2 years ago

Code of Conduct

What article on docs.github.com is affected?

https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions

What part(s) of the article would you like to see updated?

OSSF Scorecards can find issues related to token permissions and actions that are not pinned. Adding a reference to Scorecards in the token permissions and (optionally) pin actions sections of the hardening guide will help readers to take action to address these issues.

https://github.blog/2022-01-19-reducing-security-risk-oss-actions-opensff-scorecards-v4/

Additional information

No response

welcome[bot] commented 2 years ago

Thanks for opening this issue. A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

ramyaparimi commented 2 years ago

@varunsh-coder Thanks so much for opening an issue! I'll triage this for the team to take a look :eyes: