We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🌈 completed scorecard.yml warning[excessive-permissions]: overly broad workflow or job-level permissions --> .github/workflows/scorecard.yml:18:1 | 18 | permissions: read-all | --------------------- uses read-all permissions | = note: audit confidence → High 1 findings (0 ignored): 0 unknown, 0 informational, 0 low, 1 medium, 0 high
The text was updated successfully, but these errors were encountered:
It's not clear if read-all is truly necessary here or not. I opened ossf/scorecard-action#1461 to ask about it.
read-all
Sorry, something went wrong.
Seems that read-all isn't necessary, but a matter of convenience. We may want to do some testing to see how much we can restrict that.
No branches or pull requests
The text was updated successfully, but these errors were encountered: