Skip to content

CVE-2026-45793 mitigation#143

Merged
maciejlew merged 1 commit into
smsapi:masterfrom
maciejlew:CVE-2026-45793
May 20, 2026
Merged

CVE-2026-45793 mitigation#143
maciejlew merged 1 commit into
smsapi:masterfrom
maciejlew:CVE-2026-45793

Conversation

@maciejlew
Copy link
Copy Markdown
Collaborator

Restrict workflow token permissions (CVE-2026-45793)

Add explicit permissions: contents: read to prevent GITHUB_TOKEN from carrying unnecessary write scopes in the event of a Composer token leak.

graycoreio/github-actions-magento2#261

@maciejlew maciejlew self-assigned this May 20, 2026
@maciejlew maciejlew merged commit 426b423 into smsapi:master May 20, 2026
11 checks passed
@maciejlew maciejlew deleted the CVE-2026-45793 branch May 20, 2026 09:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant