Automatically create PRs with security enhancements #1070
Replies: 2 comments 1 reply
-
|
Hi @trueberryless, thanks for opening an issue! This is something I'm interested in, but you're right that it's a pretty big task 🙂 -- there are a couple of interlocking considerations here that I think would need to be addressed (or at least thought through and deemed acceptable) before extending this action to allow for PR generation as well:
TL;DR I'm concerned about introducing more sources of user error + making it too easy for people to automatically break their workflows/actions through |
Beta Was this translation helpful? Give feedback.
-
|
(Note: I'm going to convert this into a discussion topic, since it has a pretty large design space that I think would benefit from larger community feedback.) |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I recently stumbled upon this awesome security improvement project and after running the GH action I wondered where I can now find the output.
After finding it in the Security sector, I thought that this made total sense, but at the same time I wondered if it would be possible that simple fixes, like scoping permissions to jobs instead of the whole workflow would be possible automatically by creating PRs to the repo.
I am aware that this is a huge process and also kinda a visionary decision of the project. My vision would be a similar tool like Renovate, but for managing security on GH actions specifically instead of dependency management.
Feel free to share useful thoughts or just use emoji reactions for disagreement or agreement 🤝
Beta Was this translation helpful? Give feedback.
All reactions