4 ms·
There's a lack of documentation since this isn't officially released yet, but my assumption is that you need write permissions to id-token in order to generate
by Deathmax 5y ago
There's a lack of documentation since this isn't officially released yet, but my assumption is that you need write permissions to id-token in order to generate a JWT. As forked repos can at most get read access[1], presumably that would prevent a malicious fork job from generating the JWT.
[1]: https://docs.github.com/en/actions/reference/authentication-in-a-workflow#permissions-for-the-github_token https://docs.github.com/en/actions/reference/authentication-...
- chrisrpatterson 5y agoYes a malicious fork will NOT be able to get a JWT just like they are not able to get any other secrets or privledges to the repo.
- jffry 5y agoI was going to ask for a source, but I saw you've commented in the past that you're the GitHub Actions product manager. This looks like a great feature to help keep long-lived AWS secrets out of my builds entirely.