| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| ### General Best Practices | ||
|
|
||
| - Use the principle of least privilege: Only grant the specific permissions needed for your workflow. | ||
| - Regularly audit and review your workflows to ensure permissions remain appropriate for your use cases. | ||
| - Test your workflows with the intended permissions to verify they work as expected without over-permissioning. |
There was a problem hiding this comment.
I'd remove this section personally - this would be betters suited in our GitHub documentation for Actions best practices rather than in this action's README.
Sorry, something went wrong.
| ## Recommended Permissions | ||
|
|
||
| The permissions required for the `GITHUB_TOKEN` in your workflow vary depending on how you use `github-script`. To ensure secure and efficient use of this action, we recommend reviewing and setting the least privileges necessary for your use case. | ||
|
|
||
| ### Determine the Required Permissions | ||
|
|
||
| 1. **`GITHUB_TOKEN` Authentication** | ||
| GitHub automatically provides a `GITHUB_TOKEN` for workflows. You can customize the permissions granted to this token. Refer to the documentation for details: | ||
| [Permissions for the `GITHUB_TOKEN`](https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token) | ||
|
|
||
| 2. **API Calls with Installation Access Tokens** | ||
| If you're using `github-script` to make API calls requiring installation access tokens, ensure the permissions are configured appropriately for those endpoints. Learn more here: | ||
| [Permissions for installation access tokens](https://docs.github.com/en/rest/authentication/endpoints-available-for-github-app-installation-access-tokens) |
There was a problem hiding this comment.
I think we can simplify this a bit
| ## Recommended Permissions | |
| The permissions required for the `GITHUB_TOKEN` in your workflow vary depending on how you use `github-script`. To ensure secure and efficient use of this action, we recommend reviewing and setting the least privileges necessary for your use case. | |
| ### Determine the Required Permissions | |
| 1. **`GITHUB_TOKEN` Authentication** | |
| GitHub automatically provides a `GITHUB_TOKEN` for workflows. You can customize the permissions granted to this token. Refer to the documentation for details: | |
| [Permissions for the `GITHUB_TOKEN`](https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token) | |
| 2. **API Calls with Installation Access Tokens** | |
| If you're using `github-script` to make API calls requiring installation access tokens, ensure the permissions are configured appropriately for those endpoints. Learn more here: | |
| [Permissions for installation access tokens](https://docs.github.com/en/rest/authentication/endpoints-available-for-github-app-installation-access-tokens) | |
| ## Recommended permissions | |
| The permissions required for the `GITHUB_TOKEN` in your workflow vary depending on how you use `actions/github-script`. We recommend reviewing and setting the least privileges necessary for your use case. | |
| See [Permissions for the `GITHUB_TOKEN`](https://docs.github.com/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token) for details on the available permissions and [Permissions for installation access tokens](https://docs.github.com/en/rest/authentication/endpoints-available-for-github-app-installation-access-tokens) for information on what permissions each API requires. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Add new Recommended permissions section to the README file.