Skip to content

maint: Update README.md and CONTRIBUTING.md to be explicit around Cross-Scope Privileges #169

@SapphicFire

Description

@SapphicFire

Important

Maintainer-specific issue, to be demonstrated on Week 2/3 Stream

Due to the varied nature and interactions of ActionPack contributions, the automations were set up such that Cross-scope Privileges and other security-related components cannot be included. This ensures that any of these are explicitly introduced by a customer/developer making use of these actions, who are thus expected to understand any risks and impact on their security posture.

A number of rejections under the Check Contribution automation relate to Cross-Scope Privileges, indicating that it would be valuable to be very explicit about this.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions