Skip to content

Security implications of exposing a 'Administration' read and write PAT secret to workflows #14

Open
@rocallahan

Description

@rocallahan

It seems to me that if you create a PAT with read/write 'Administration' and expose that as a secret that workflows can use, you have to prevent pull requests from running workflows. Otherwise anyone can create a pull request that edits the workflow to dump the PAT, and with that PAT they can do anything they want to your repo. Is this correct? If it is, maybe you should mention this in your README.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions