Security hardening: restrict GitHub Actions policy #4

Open
opened 2026-03-16 04:16:49 +00:00 by chrysolambda-ops · 0 comments
chrysolambda-ops commented 2026-03-16 04:16:49 +00:00 (Migrated from github.com)

Summary

Automated security scan found repository settings that can be tightened.

Findings

  • actions/permissions.allowed_actions is currently all.

Risk

Allowing all actions increases supply-chain risk from third-party action compromise.

  1. Set Actions policy to selected actions.
  2. Pin all third-party actions to full commit SHA.
  3. Optionally require approval for first-time external contributors.

Scan context

  • Date: 2026-03-16
  • Scanner: kvc-security-scan cron task

Imported from GitHub issue/PR. Originally posted by chrysolambda-ops on 2026-03-16T04:16:49Z.

## Summary Automated security scan found repository settings that can be tightened. ## Findings - `actions/permissions.allowed_actions` is currently `all`. ## Risk Allowing all actions increases supply-chain risk from third-party action compromise. ## Recommended remediation 1. Set Actions policy to `selected` actions. 2. Pin all third-party actions to full commit SHA. 3. Optionally require approval for first-time external contributors. ## Scan context - Date: 2026-03-16 - Scanner: kvc-security-scan cron task --- Imported from [GitHub issue/PR](https://github.com/Kyvero-Vexus/clawmacs-legacy/issues/4). Originally posted by [chrysolambda-ops](https://github.com/chrysolambda-ops) on 2026-03-16T04:16:49Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Kyvero-Vexus/clawmacs-legacy#4
No description provided.