Skip to content

Conversation

malice00
Copy link
Collaborator

@malice00 malice00 commented Jun 19, 2025

By default, the checkout-action persists the credential into the workspace. This is an insecure practice, so this PR sets this option to false on all checkouts.

This fixes #1881

Signed-off-by: Roland Asmann <roland.asmann@gmail.com>
@malice00 malice00 requested a review from prabhu as a code owner June 19, 2025 08:24
@malice00 malice00 merged commit 5460f0f into master Jun 19, 2025
72 checks passed
@malice00 malice00 deleted the fix/checkout_credentials branch June 19, 2025 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[security] Add persist-credentials: false to our checkout steps
1 participant