Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
usd877 authored Feb 15, 2025
1 parent f58e260 commit b6f72a6
Showing 1 changed file with 17 additions and 0 deletions.
17 changes: 17 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,23 @@ The following variables are set in the `.env` file created by the pipeline:
- If you encounter issues with database migrations, verify your database settings in `settings.py`.
- Review the logs in the GitHub Actions tab for detailed error messages.

# Security Improvements in GitHub Actions Workflows

## Overview
We have updated the GitHub Actions workflows to ensure minimal permissions are used, addressing the issue `CKV2_GHA_1: Ensure top-level permissions are not set to write-all`.

### Changes Made
- Replaced `write-all` permissions with specific permissions such as:
- `contents: read`
- `pull-requests: write`
- `packages: write`
- Added detailed comments to explain the purpose of each permission.

### Debugging Tips
- Ensure that all required permissions are explicitly defined in the workflow files.
- Review the logs in the GitHub Actions tab for detailed error messages.
- Use tools like Checkov or CodeQL to scan your workflows for security issues and generate SARIF reports for further analysis.

# Security Gateway Pipeline

## Overview
Expand Down

0 comments on commit b6f72a6

Please sign in to comment.