CI runs pull request code with a write token
- Weakness
- CWE-829
- Where
- Release workflow in the project’s CI
- Impact
- An outside contributor could run code with permission to push to the repository.
- Fix
- Run untrusted pull requests without secrets, cut token permissions to read-only, and pin third-party actions.









