Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update InstructLab organization's Settings->Actions->General to limit action usage #54

Open
bjhargrave opened this issue May 20, 2024 · 8 comments
Labels

Comments

@bjhargrave
Copy link
Contributor

bjhargrave commented May 20, 2024

Given the policy in #45, we need to update the organization settings to enforce the allowed providers of actions.

Once #45 is approved and merged, and a full audit of existing GitHub action usage is complete, the organization settings need to configured.

@russellb
Copy link
Member

@bjhargrave does the list you have in #45 cover all currently used actions across all repos? Otherwise, it seems like we can't do the configuration until we know it doesn't break anything. Starting with everything currently in use seems fine though

@bjhargrave
Copy link
Contributor Author

@bjhargrave does the list you have in #45 cover all currently used actions across all repos?

It is not exhaustive. There are other repos in the org which I will need to survey. This issue is to capture the need to update org settings when we have a final list.

@russellb
Copy link
Member

Thanks, @bjhargrave . Can you make a small edit to clarify, something like:

Once #45 is approved and merged, the organization settings need to configured.

to

Once #45 is approved and merged and a full audit of existing github action usage is complete, the organization settings need to configured.

I just wanted to clarify that the audit is still a to-do item before we can update settings.

@nathan-weinberg
Copy link
Member

Has this been done?

@russellb
Copy link
Member

Has this been done?

fairly certain thee audit is not complete?

Copy link

This issue has been automatically marked as stale because it has not had activity within 90 days. It will be automatically closed if no further activity occurs within 30 days.

@github-actions github-actions bot added the stale label Aug 28, 2024
@nathan-weinberg
Copy link
Member

@instructlab/oversight-committee please confirm if this is done and close it if it is

@jjasghar
Copy link
Member

It looks like we do not have an allow list of actions done yet. You can use any action or reuseable workflow:
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants