qos-ch / reload4j

reload4j is a drop-in replacement for log4j 1.2.17
Apache License 2.0
148 stars 22 forks source link

Add GitHub token permissions for GitHub Actions workflow #54

Closed ceki closed 2 years ago

ceki commented 2 years ago

Related issue submitted to SLF4J/logback projects by @varunsh-coder Varun Sharma varunsh@stepsecurity.io

GitHub recommends defining minimum GITHUB_TOKEN permissions for securing GitHub Actions workflows.

See: GitHub Actions: Control permissions for GITHUB_TOKEN About the GITHUB_TOKEN secret

The Open Source Security Foundation (OpenSSF) Scorecards treats not setting token permissions as a high-risk issue

ceki commented 2 years ago

Fixed in baf4eab6