Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Think about restricting runs on GitHub Actions #23

Open
paulo-ferraz-oliveira opened this issue Sep 16, 2024 · 1 comment
Open

Think about restricting runs on GitHub Actions #23

paulo-ferraz-oliveira opened this issue Sep 16, 2024 · 1 comment
Labels
security consideration Security consideration

Comments

@paulo-ferraz-oliveira
Copy link
Collaborator

Per the settings: https://github.com/erlef/otp_builds/settings/actions

We should choose (once we know which ones we'll use) a given number of actions and add those under "Allow erlef, and select non-erlef, actions and reusable workflows".

@paulo-ferraz-oliveira paulo-ferraz-oliveira added the security consideration Security consideration label Sep 16, 2024
@paulo-ferraz-oliveira
Copy link
Collaborator Author

Should wait on #1 to understand what is feasible/reasonable. We also need to pin the commit SHAs if we're into security hardening the repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security consideration Security consideration
Projects
None yet
Development

No branches or pull requests

1 participant