-
-
Notifications
You must be signed in to change notification settings - Fork 123
Open
Labels
enhancementNew feature or requestNew feature or requesttriageIssue is being triagedIssue is being triaged
Description
Pre-submission checks
- I am not reporting a bug (crash, false positive/negative, etc). These must be filed via the bug report template.
- I have looked through both the open and closed issues for a duplicate request.
What's the problem this feature will solve?
I'm auditing the permissions in my workflow files and I haven't been able to identify why the actions: read permission is required by the GH_TOKEN that zizmor itself uses for its checks when it runs on GitHub Actions.
I looked at the list of audit rules that don't work offline to see if I could figure out which one requires it, but with no luck.
Candidates:
impostor-commitknown-vulnerable-actionsref-confusionstale-action-refs
Previous issue: #608
Describe the solution you'd like
Could you confirm why this permission is required by zizmor and which audit rule uses it?
Additional context
Big fan of zizmor!
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requesttriageIssue is being triagedIssue is being triaged