ci,k8s: harden workflow permissions, pin actions, and lock down container security context #1
Loading…
Reference in a new issue
No description provided.
Delete branch "mend/chant-audit-mt1yr8hm"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Moved from https://github.com/jhgaylor/otfl/pull/2 (the repo now lives on Forgejo).
Note: this edits
.github/workflows/build.yml, which moved to.forgejo/workflows/build.yml, so that part needs porting before merge.A
chant auditflagged 10 merge-worthy findings on thebuildworkflow andk8s/deployment.yaml; this covers the three you picked.permissions: contents: readfor least privilege.runAsNonRoot: true,readOnlyRootFilesystem: true, andcapabilities.drop: [ALL]; this one wants review — verified the app only writes to the DATA_DIR PVC mount, but please confirm before merging.View command line instructions
Manual merge helper
Use this merge commit message when completing the merge manually.
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.