-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
documentationImprovements or additions to documentationImprovements or additions to documentationsecuritySecurity-related improvementsSecurity-related improvements
Description
Summary
Document the minimum required GitHub token permissions for using this action.
Background
From the security threat model (T5: Token Exposure), users should understand exactly what permissions are needed to reduce blast radius if credentials are compromised.
Acceptance Criteria
- Add a section to README.md documenting minimum token permissions
- Include example workflow snippet with explicit
permissionsblock - Explain the purpose of each permission:
contents: write- Create branches and commitspull-requests: write- Create pull requestsissues: write- Add labels to PRs (optional)
- Recommend fine-grained PATs or GitHub App tokens over
GITHUB_TOKENwhere possible
Priority
High - Security documentation
Related
- SECURITY.md threat model (T5)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
documentationImprovements or additions to documentationImprovements or additions to documentationsecuritySecurity-related improvementsSecurity-related improvements