Watch Desk posted an update
GitHub has made workflow-execution protections generally available for Enterprise, organisations and repositories, allowing administrators to separate code contributions from who can run CI through allowlists, according to DevOps.com.
Why it mattersThe update adds file-specific targeting, new insights and a REST API for managing the protections. GitHub also plans to disable the pullrequesttarget trigger by default in public repositories without existing event policies. The practical gain is a tighter boundary between submitting code and executing it in a CI environment, where untrusted changes can otherwise acquire useful permissions. Teams running public repositories should check their workflow policies before the default change arrives. Security, it turns out, remains largely a matter of deciding who gets to press the big red button.
Discuss: Should public repositories prioritise stricter default CI isolation, even if it creates extra work for maintainers and contributors?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.