Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CD: Github Security - Ensure only app devs can create tags, releases and release branches #467

Open
sdsantos opened this issue Feb 11, 2025 · 1 comment
Assignees

Comments

@sdsantos
Copy link
Contributor

sdsantos commented Feb 11, 2025

Confirmed:

  • The Probe Team is composed of Arturo, Sérgio, Maja, Norbel and DecFox
  • Only the Probe Team has Write (and Admin) access to Github
  • Only those who Write access to the repository can create/edit/delete releases
  • Environment secrets for Github actions can only be used by users with collaborator access to the repository
  • PRs created from forks don't have access to secrets

Done:

  • Limit the creation of release branches to the Probe Team
  • Limit the creation of tags to the Probe Team

Image Image
@sdsantos sdsantos self-assigned this Feb 11, 2025
@sdsantos
Copy link
Contributor Author

@hellais @aanorbel Let me know if you guys have any other concern regarding hardening the security of this repository, related with the future automated releases.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant