Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
This repository was archived by the owner on Oct 10, 2025. It is now read-only.

Comments

Close side panel

chore(ci): apply security best practices#31

Merged
JPLachance merged 1 commit intomaincoveooss/feign-error-decoder:mainfrom
chore/GHA-050715-stepsecurity-remediationcoveooss/feign-error-decoder:chore/GHA-050715-stepsecurity-remediationCopy head branch name to clipboard
May 28, 2025
Merged

chore(ci): apply security best practices#31
JPLachance merged 1 commit intomaincoveooss/feign-error-decoder:mainfrom
chore/GHA-050715-stepsecurity-remediationcoveooss/feign-error-decoder:chore/GHA-050715-stepsecurity-remediationCopy head branch name to clipboard

Conversation

@stepsecurity-app
Copy link
Contributor

Summary

This pull request has been generated by StepSecurity as part of your enterprise subscription to ensure compliance with recommended security best practices. Please review and merge the pull request to apply these security enhancements.

Security Fixes

Harden Runner

Harden-Runner is an open-source security agent for the GitHub-hosted runner to prevent software supply chain attacks. It prevents exfiltration of credentials, detects tampering of source code during build, and enables running jobs without sudo access.

Least Privileged GitHub Actions Token Permissions

The GITHUB_TOKEN is an automatically generated secret to make authenticated calls to the GitHub API. GitHub recommends setting minimum token permissions for the GITHUB_TOKEN.

Pinned Dependencies

Pinning GitHub Actions to specific versions or commit SHAs ensures that your workflows remain consistent and secure.
Unpinned actions can lead to unexpected changes or vulnerabilities caused by upstream updates.

Feedback

For bug reports, feature requests, and general feedback; please create an issue in step-security/secure-repo or contact us via our website.

@JPLachance JPLachance merged commit 562d070 into main May 28, 2025
2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Morty Proxy This is a proxified and sanitized view of the page, visit original site.