Skip to content

[StepSecurity] ci: Harden GitHub Actions#6802

Merged
yadvr merged 1 commit intoapache:mainfrom
step-security-bot:stepsecurity_remediation_1664829954
Oct 8, 2022
Merged

[StepSecurity] ci: Harden GitHub Actions#6802
yadvr merged 1 commit intoapache:mainfrom
step-security-bot:stepsecurity_remediation_1664829954

Conversation

@step-security-bot
Copy link
Copy Markdown
Contributor

Summary

This is an automated pull request generated by Secure Workflows at the request of @jbampton. Please merge the Pull Request to incorporate the requested changes. Please tag @jbampton on your message if you have any questions related to the PR. You can also engage with the StepSecurity team by tagging @step-security-bot.

Security Fixes

Least Privileged GitHub Actions Token Permissions

The least privilged token permissions were calculate using Secure WorkFlows based on the actions included in the GitHub Workflow files. This is recommended by GitHub as well as The Open Source Security Foundation (OpenSSF).

Feedback

For bug reports, feature requests, and general feedback; please create an issue in step-security/secure-workflows or contact us via our website.

@boring-cyborg
Copy link
Copy Markdown

boring-cyborg Bot commented Oct 3, 2022

Congratulations on your first Pull Request and welcome to the Apache CloudStack community! If you have any issues or are unsure about any anything please check our Contribution Guide (https://github.com/apache/cloudstack/blob/main/CONTRIBUTING.md)
Here are some useful points:

@yadvr yadvr added this to the 4.18.0.0 milestone Oct 4, 2022
@codecov
Copy link
Copy Markdown

codecov Bot commented Oct 4, 2022

Codecov Report

Merging #6802 (18c104a) into main (4e2f461) will increase coverage by 0.00%.
The diff coverage is n/a.

@@            Coverage Diff            @@
##               main    #6802   +/-   ##
=========================================
  Coverage     10.52%   10.52%           
- Complexity     6782     6785    +3     
=========================================
  Files          2464     2464           
  Lines        244168   244168           
  Branches      38205    38205           
=========================================
+ Hits          25692    25705   +13     
+ Misses       215243   215228   -15     
- Partials       3233     3235    +2     
Impacted Files Coverage Δ
...rg/apache/cloudstack/quota/QuotaStatementImpl.java 40.26% <0.00%> (+3.98%) ⬆️
...dstack/network/contrail/model/ModelObjectBase.java 28.84% <0.00%> (+7.69%) ⬆️

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@yadvr yadvr merged commit de8aae1 into apache:main Oct 8, 2022
@boring-cyborg
Copy link
Copy Markdown

boring-cyborg Bot commented Oct 8, 2022

Awesome work, congrats on your first merged pull request!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants