StepSecurity App
GitHub App
StepSecurity App
GitHub App
This App enables advanced scenarios for the StepSecurity Platform, e.g.
- Analysis of private GitHub Actions
- Creation of GitHub issues and pull requests for Action misconfigurations, e.g. over-privileged GitHub token permissions
- Integration with GitHub Advanced Security
- Enforce Workflow Runs Policies to block workflow runs that do not meet organization policies
It needs the following permissions:
- Administration Read: To check branch protection of private Actions
- Contents Write: To evaluate score for private Actions and fixes for Action misconfigurations
- Pull Requests Write: To evaluate score for private Actions and fix GitHub Actions workflows
- Issues Write: To create issues to recommend fixes for Action misconfigurations
- Code Scanning Alerts Write: To create GitHub Advanced Security findings to recommend fixes for Action misconfigurations
- Actions Write: To cancel workflow runs that do not meet organization policies.
This App should only be installed after the https://github.com/apps/stepsecurity-actions-security App
Developer
StepSecurity App is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation.
Report abuse