Skip to content

Conversation

@luojiyin1987
Copy link

No description provided.

  - Move READ_ACCESS_TOKEN from job-level to step-level environment variables
  - Reduces token exposure scope to only necessary steps
  - Prevents token leakage in workflow logs from other steps
  - Maintains existing functionality while enhancing security
@luojiyin1987
Copy link
Author

GOOGLE_APPLICATION_CREDENTIALS_BASE64 and MYSTEN_SPREEDSHEET_ID are not being used, should they be removed?

@luojiyin1987
Copy link
Author

It seems this permission (pull-requests: write) is not being used

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant