Git Product home page Git Product logo

Comments (2)

mpkorstanje avatar mpkorstanje commented on August 16, 2024

We can also limit the actions allowed in the organisation in a few different ways

  • Only allow actions, cucumber org actions.
  • Only allow actions, cucumber org actions and actions from verified publishers.

We currently have these non-cucumber non-github provided actions, I can't tell which ones are verified publishers:

mpkorstanje@nyx:~/Projects/cucumber/code-search$ grep -r uses: | grep ".github"  | cut -d ":" -f 3 | sort | uniq | grep -v cucumber | grep -v actions
 8398a7/action-slack@v3
 arduino/setup-protoc@v1
 aurelien-baudet/workflow-dispatch@v2
 codecov/codecov-action@v1
 codecov/codecov-action@v3
 coverallsapp/github-action@master
 dart-lang/[email protected]
 docker/bake-action@v2
 docker/build-push-action@v3
 docker/login-action@v2
 docker/setup-buildx-action@v2
 docker/setup-qemu-action@v2
 erlef/setup-beam@v1
 GabrielBB/xvfb-action@v1
 golangci/[email protected]
 goreleaser/goreleaser-action@v2
 goreleaser/[email protected]
 HaaLeo/publish-vscode-extension@v1
 marocchino/sticky-pull-request-comment@v2
 mymindstorm/setup-emsdk@v11
 ocaml/setup-ocaml@v2
 pulumi/setup-pulumi@v2
 reactivecircus/android-emulator-runner@v2
 ruby/setup-ruby@v1
 shivammathur/setup-php@v2
 snok/install-poetry@v1
 softprops/action-gh-release@v1

from common.

mpkorstanje avatar mpkorstanje commented on August 16, 2024

Projects that use the cucumber/action-create-github-release that would definitely need elevated permissions.

mpkorstanje@nyx:~/Projects/cucumber/code-search$ grep -rl cucumber/action-create-github-release | cut -d '/' -f 1
cucumber-expressions
blockly
cucumber-parent
action-get-versions
gherkin
message-streams
action-publish-rubygem
action-publish-sbt
action-publish-nuget
action-publish-hex
action-create-github-release
action-create-github-release
action-create-github-release
action-create-github-release
action-create-github-release
action-create-github-release
gherkin-streams
cucumber-jvm-scala
action-publish-npm
multi_test
html-formatter
compatibility-kit
action-create-release-pr
cucumber-js-pretty-formatter
ci-environment
cucumber-js
react-components
language-server
action-publish-subrepo
screenplay.js
build
cucumber-ruby
language-service
cucumber-ruby-wire
cucumber-json-converter
monaco
cucumber-android
messages
action-publish-mvn
gherkin-utils
action-publish-pypi
microdata
split-java
tag-expressions
query
action-publish-cpan
cucumber-ruby-core
cucumber-rails
release-tests
cucumber-jvm

from common.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.