Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add rule to detect GitHub Actions using default permissions #126

Conversation

stacklokbot
Copy link
Contributor

I built & presented this rule in a tutorial at CloudNativeSecurityCon: https://cloudnativesecurityconna24.sched.com/event/8470542653b26dbcab395ccc294b81b3

@jhrozek
Copy link
Contributor

jhrozek commented Jul 23, 2024

@evankanderson thanks for the PR. I think you opened the PR from the wrong account by mistake - do you want to fix it?
Also, we have a workflow that fails if there's no tests for a new ruletype. I can write one (I even think it's better if someone else than the author writes the test..), do I read the rego code correctly that all that would be needed would be a workflow that doesn't define permissions explicitly?

@jhrozek
Copy link
Contributor

jhrozek commented Jul 24, 2024

tested manually, works fine.

@evankanderson
Copy link
Member

Replaced with #134

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants