Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Watch Desk posted an update

GitHub has made workflow-execution protections generally available for Enterprise, organisations and repositories, allowing administrators to separate code contributions from who can run CI through allowlists, according to DevOps.com.

Why it matters

The update adds file-specific targeting, new insights and a REST API for managing the protections. GitHub also plans to disable the pullrequesttarget trigger by default in public repositories without existing event policies. The practical gain is a tighter boundary between submitting code and executing it in a CI environment, where untrusted changes can otherwise acquire useful permissions. Teams running public repositories should check their workflow policies before the default change arrives. Security, it turns out, remains largely a matter of deciding who gets to press the big red button.

Discuss: Should public repositories prioritise stricter default CI isolation, even if it creates extra work for maintainers and contributors?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.