kubescape / kubevuln

Kubevuln is an in-cluster component of the Kubescape security platform. It scans container images for vulnerabilities, using Grype as its engine.
Apache License 2.0
18 stars 19 forks source link

add top level permissions: read-all for openssf #171

Closed matthyx closed 1 year ago

matthyx commented 1 year ago

PR Type:

Enhancement


PR Description:

This PR introduces a new top-level permission, 'read-all', for OpenSSF. This permission has been added to the workflows for when a pull request is created and when a pull request is merged. The changes aim to enhance the security and control over the repository by specifying the level of access required for these workflows.


PR Main Files Walkthrough:

files: `.github/workflows/pr-created.yaml`: Added 'read-all' permission at the top level. Also, some formatting changes have been made. `.github/workflows/pr-merged.yaml`: Added 'read-all' permission at the top level. Some formatting changes have been made and the condition for the 'pr-merged' job has been updated to skip if not merged.
codiumai-pr-agent-free[bot] commented 1 year ago

PR Analysis

How to use

To invoke the PR-Agent, add a comment using one of the following commands: /review [-i]: Request a review of your Pull Request. For an incremental review, which only considers changes since the last review, include the '-i' option. /describe: Modify the PR title and description based on the contents of the PR. /improve [--extended]: Suggest improvements to the code in the PR. Extended mode employs several calls, and provides a more thorough feedback. /ask \<QUESTION>: Pose a question about the PR. /update_changelog: Update the changelog based on the PR's contents.

To edit any configuration parameter from configuration.toml, add --config_path=new_value For example: /review --pr_reviewer.extra_instructions="focus on the file: ..." To list the possible configuration parameters, use the /config command.

matthyx commented 1 year ago

closes #170