Skip to content

Conversation

step-security-bot
Copy link
Contributor

Summary

This pull request is created by StepSecurity at the request of @filipchristiansen. Please merge the Pull Request to incorporate the requested changes. Please tag @filipchristiansen on your message if you have any questions related to the PR.

Security Fixes

Least Privileged GitHub Actions Token Permissions

The GITHUB_TOKEN is an automatically generated secret to make authenticated calls to the GitHub API. GitHub recommends setting minimum token permissions for the GITHUB_TOKEN.

Feedback

For bug reports, feature requests, and general feedback; please email support@stepsecurity.io. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot bot@stepsecurity.io

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@filipchristiansen filipchristiansen force-pushed the stepsecurity_remediation_1741796159 branch from 126092e to 252dfc5 Compare March 12, 2025 22:06
@cyclotruc cyclotruc merged commit 9451299 into coderamp-labs:main Mar 13, 2025
12 of 18 checks passed
filipchristiansen pushed a commit that referenced this pull request Mar 13, 2025
Signed-off-by: Filip Christiansen <22807962+filipchristiansen@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants