Skip to content

Conversation

caugner
Copy link
Contributor

@caugner caugner commented Oct 8, 2025

Description

Adds persist-credentials: false to all actions/checkout workflow steps.

Motivation

Applies security best practices. It prevents persistance of the GITHUB_TOKEN in the local git config.

Additional details

Related issues and pull requests

Part of mdn/fred#883.

@caugner caugner requested a review from a team as a code owner October 8, 2025 10:22
@caugner caugner requested review from pepelsbey and removed request for a team October 8, 2025 10:22
Copy link
Member

@pepelsbey pepelsbey left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@caugner caugner merged commit 3b112d5 into main Oct 13, 2025
2 checks passed
@caugner caugner deleted the workflows-checkout-without-persist-credentials branch October 13, 2025 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants