Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Github actions updates and setup dependabot #8624

Merged
merged 6 commits into from
Jul 1, 2022

Conversation

mcspr
Copy link
Collaborator

@mcspr mcspr commented Jun 30, 2022

@wrt54g wrt54g mentioned this pull request Jul 1, 2022
@mcspr mcspr merged commit c12a6b4 into esp8266:master Jul 1, 2022
@mcspr mcspr deleted the dependabot/actions branch July 1, 2022 19:24
hasenradball pushed a commit to hasenradball/Arduino that referenced this pull request Nov 18, 2024
* github: actions/checkout v2 -> v3

* github: actions/cache v2 -> v3

* github: actions/setup-python v2 -> v4

* github: dependabot for actions

* github: 'restricted' mode for token permissions

noticed at https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

whenever external action uses our token, overall workflow 'permissions:' apply
https://docs.github.com/en/actions/security-guides/automatic-token-authentication
https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token

ref. apps documentation to understand which permissions API endpoints need
https://docs.github.com/en/rest/overview/permissions-required-for-github-apps

* missed tag-to-draft action
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant