Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

[StepSecurity] ci: Harden GitHub Actions tokens#27202

Merged
TravisEz13 merged 1 commit into
PowerShell:masterPowerShell/PowerShell:masterfrom
step-security-bot:chore/GHA-072003-stepsecurity-remediationstep-security-bot/PowerShell:chore/GHA-072003-stepsecurity-remediationCopy head branch name to clipboard
Apr 7, 2026
Merged

[StepSecurity] ci: Harden GitHub Actions tokens#27202
TravisEz13 merged 1 commit into
PowerShell:masterPowerShell/PowerShell:masterfrom
step-security-bot:chore/GHA-072003-stepsecurity-remediationstep-security-bot/PowerShell:chore/GHA-072003-stepsecurity-remediationCopy head branch name to clipboard

Conversation

@step-security-bot
Copy link
Copy Markdown
Contributor

Summary

This pull request is created by StepSecurity at the request of @TravisEz13. Please merge the Pull Request to incorporate the requested changes. Please tag @TravisEz13 on your message if you have any questions related to the PR.

Security Fixes

Least Privileged GitHub Actions Token Permissions

The GITHUB_TOKEN is an automatically generated secret to make authenticated calls to the GitHub API. GitHub recommends setting minimum token permissions for the GITHUB_TOKEN.

Feedback

For bug reports, feature requests, and general feedback; please email support@stepsecurity.io. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot bot@stepsecurity.io

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@step-security-bot step-security-bot requested review from a team and jshigetomi as code owners April 7, 2026 20:03
@TravisEz13 TravisEz13 added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Apr 7, 2026
@TravisEz13 TravisEz13 enabled auto-merge (squash) April 7, 2026 20:04
@TravisEz13 TravisEz13 changed the title [StepSecurity] ci: Harden GitHub Actions [StepSecurity] ci: Harden GitHub Actions tokens Apr 7, 2026
@TravisEz13 TravisEz13 merged commit 601f016 into PowerShell:master Apr 7, 2026
41 of 42 checks passed
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
daxian-dbw pushed a commit to daxian-dbw/PowerShell that referenced this pull request Apr 9, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
JustinGrote pushed a commit to JustinGrote/PowerShell that referenced this pull request Jun 2, 2026
Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backport-7.4.x-Done Backport-7.5.x-Done Backport-7.6.x-Done CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.