Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

List minimum permissions in README.md

Đang mở
#249 0 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
38/100
Loại issue
Tài liệu
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
github-actions
Lĩnh vực
ci-cd, documentation

Hướng nghiên cứu

Bắt đầu với README.md và các ví dụ mã liên quan, sau đó xem xét cách các workflow devcontainers/ci sử dụng GITHUB_TOKEN và các thông tin xác thực khác. Ghi lại các quyền tối thiểu cần thiết trong một phần README mới và cập nhật các ví dụ áp dụng để cài đặt quyền của chúng khớp với nhau.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

GitHub recommends users limit the permissions of any third-party actions: [^1]

  • Use credentials that are minimally scoped
    • Make sure the credentials being used within workflows have the least privileges required, and be mindful that any user with write access to your repository has read access to all secrets configured in your repository.
    • Actions can use the GITHUB_TOKEN by accessing it from the github.token context. For more information, see "Contexts." You should therefore make sure that the GITHUB_TOKEN is granted the minimum required permissions. It's good security practice to set the default permission for the GITHUB_TOKEN to read access only for repository contents. The permissions can then be increased, as required, for individual jobs within the workflow file. For more information, see "Automatic token authentication."

Can you please list the required permissions [^2] for the devcontainers/ci in a new section of the README.md and in the relevant code examples?

[^1]: GitHub Docs, security hardening, using secrets
[^2]: GitHub Docs, workflow syntax, permissions

Ngôn ngữ chính
TypeScript
Star
499
Fork
101
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của devcontainers/ci

Tất cả issue của devcontainers/ci

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.