GithubHelp home page GithubHelp logo

Comments (3)

jcfr avatar jcfr commented on June 3, 2024

Specific instruction are documented here:

from slicer.

jcfr avatar jcfr commented on June 3, 2024

Given the open-source nature of the Slicer project, I don't see an issue granting the scorecard.yml workflow read access to the administration scope1.

@jamesobutler @pieper @sjh26 @lassoan Do you have any concern ?

Read access associated with the Administration scope

GET /repos/{owner}/{repo}/actions/permissions
GET /repos/{owner}/{repo}/actions/permissions/access
GET /repos/{owner}/{repo}/actions/permissions/selected-actions
GET /repos/{owner}/{repo}/actions/permissions/workflow
GET /repos/{owner}/{repo}/actions/runners
GET /repos/{owner}/{repo}/actions/runners/downloads
GET /repos/{owner}/{repo}/actions/runners/{runner_id}
GET /repos/{owner}/{repo}/actions/runners/{runner_id}/labels
GET /repos/{owner}/{repo}/autolinks
GET /repos/{owner}/{repo}/autolinks/{autolink_id}
GET /repos/{owner}/{repo}/automated-security-fixes
GET /repos/{owner}/{repo}/branches/{branch}/protection
GET /repos/{owner}/{repo}/branches/{branch}/protection/enforce_admins
GET /repos/{owner}/{repo}/branches/{branch}/protection/required_pull_request_reviews
GET /repos/{owner}/{repo}/branches/{branch}/protection/required_signatures
GET /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks
GET /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks/contexts
GET /repos/{owner}/{repo}/branches/{branch}/protection/restrictions
GET /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/apps
GET /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/teams
GET /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/users
GET /repos/{owner}/{repo}/interaction-limits
GET /repos/{owner}/{repo}/invitations
GET /repos/{owner}/{repo}/keys
GET /repos/{owner}/{repo}/keys/{key_id}
GET /repos/{owner}/{repo}/tags/protection
GET /repos/{owner}/{repo}/teams
GET /repos/{owner}/{repo}/traffic/clones
GET /repos/{owner}/{repo}/traffic/popular/paths
GET /repos/{owner}/{repo}/traffic/popular/referrers
GET /repos/{owner}/{repo}/traffic/views
GET /repos/{owner}/{repo}/vulnerability-alerts
GET /user/repository_invitations

Footnotes

  1. https://docs.github.com/en/rest/overview/permissions-required-for-fine-grained-personal-access-tokens?apiVersion=2022-11-28#repository-permissions-for-administration

from slicer.

jamesobutler avatar jamesobutler commented on June 3, 2024

Yes I see no problem adding a token for read access to the administration information. @jcfr following the instructions at https://github.com/ossf/scorecard-action#authentication-with-fine-grained-pat-optional makes sense. Since you are a main Slicer developer, re-upping the token whenever it expires seems reasonable and a low effort future task to enable the scorecard action to have access to what it needs for the additional checks.

from slicer.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.