Commit 17d7388
Add least-privilege permissions to triage workflow
Add explicit permissions: block (pull-requests: write, issues: write) to
constrain GITHUB_TOKEN scope on pull_request_target trigger.
Ref: https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>1 parent 6e8d568 commit 17d7388
1 file changed
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
11 | 15 | | |
12 | 16 | | |
13 | 17 | | |
| |||
0 commit comments