mirror of
https://github.com/actions/upload-artifact.git
synced 2025-01-27 19:35:29 +00:00
Add Recommended Permissions
To reduce risk of over-privileged tokens, we are adding recommended permissions to popular GitHub-owned Actions READMEs
This commit is contained in:
parent
65c4c4a1dd
commit
8d131b7299
@ -478,3 +478,11 @@ At the bottom of the workflow summary page, there is a dedicated section for art
|
||||
There is a trashcan icon that can be used to delete the artifact. This icon will only appear for users who have write permissions to the repository.
|
||||
|
||||
The size of the artifact is denoted in bytes. The displayed artifact size denotes the size of the zip that `upload-artifact` creates during upload.
|
||||
|
||||
# Recommended Permissions
|
||||
|
||||
The `actions/upload-artifact` workflow relies on an internal authentication pattern and does not use the GITHUB_TOKEN, to reduce risk of over-privileged token, jobs that use `actions/upload-artifact` should set permissions to none:
|
||||
|
||||
```yaml
|
||||
permissions: {}
|
||||
```
|
||||
|
Loading…
Reference in New Issue
Block a user