mirror of
https://codeberg.org/icewind/attic-action.git
synced 2026-06-03 17:44:07 +02:00
README: clarify on security
This commit is contained in:
parent
6ca1a9b396
commit
03b6d2e977
1 changed files with 10 additions and 1 deletions
11
README.md
11
README.md
|
|
@ -56,7 +56,16 @@ jobs:
|
|||
|
||||
See [action.yml](action.yml) for all options.
|
||||
|
||||
---
|
||||
## Security
|
||||
|
||||
Cachix auth token and signing key need special care as they give read and write access to your caches.
|
||||
|
||||
[As per GitHub Actions' security model](https://help.github.com/en/actions/automating-your-workflow-with-github-actions/creating-and-using-encrypted-secrets#using-encrypted-secrets-in-a-workflow):
|
||||
|
||||
> Anyone with write access to a repository can create, read, and use secrets.
|
||||
|
||||
Which means all developers with push access can read your secrets and write to your cache.
|
||||
|
||||
|
||||
## Hacking
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue