Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-38426

Fix the permissions for GitHub workflows

    XMLWordPrintableJSON

Details

    • Bug
    • Status: In Progress
    • Major
    • Resolution: Unresolved
    • 3.2.1
    • None
    • Build
    • None

    Description

      1. The workflow files don't have permission restricted. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
      2. In some of the workflows, the actions aren't pinned by SHA. https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies

      Attachments

        Activity

          People

            Unassigned Unassigned
            turris-nivasan Naveen S
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: