You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 3e132b1
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/config-apply-fixes.md
+11-2Lines changed: 11 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,14 +21,23 @@ Only for the GitHub Actions workflow file, if you use it:
21
21
22
22
You may see GitHub permission errors, or workflows not running on the new commit.
23
23
24
+
> **Security warning — Personal Access Tokens (PAT) are NOT recommended.**
25
+
> Open-source projects have been heavily targeted by supply-chain attacks in recent months, and a leaked or compromised PAT can give attackers broad write access to your repository — better safe than sorry!
26
+
> Before adding a `PAT` secret, ask yourself if you really need workflows to re-trigger automatically after MegaLinter pushes a fix commit. In most cases the simpler and safer workaround is enough:
27
+
>
28
+
> -**Manually re-run the failed workflow** from the GitHub Actions tab, or
29
+
> -**Push another commit** on the branch (even an empty one: `git commit --allow-empty -m "trigger CI"`) so GitHub re-runs the workflows.
30
+
>
31
+
> Only set up a PAT if you fully understand the trade-off. If you do, use a **fine-grained token scoped to a single repository** with the **minimum required permissions**, and rotate it regularly.
32
+
24
33
To solve these issues, apply one of the following solutions.
25
34
26
-
- Method 1: The most secured
35
+
- Method 1: The most secured (still discouraged — read the warning above)
27
36
-[Create a Fine-Grained Personal Access Token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/creating-a-personal-access-token#creating-a-fine-grained-personal-access-token), scoped only to your repository and with **Contents: Read/Write**, then copy the PAT value
28
37
-[Define environment secret variable](https://docs.github.com/en/actions/security-guides/encrypted-secrets#creating-encrypted-secrets-for-an-environment) named **PAT** on your repository, and paste the PAT value
29
38
- Update your GitHub Actions workflow to add the environment name
30
39
31
-
-- Method 2: Easier, but any contributor with write access can see your Personal Access Token, so use it only on private repositories.
40
+
-- Method 2: Easier, but **strongly discouraged** — any contributor with write access can see your Personal Access Token, so use it only on private repositories.
32
41
-[Create a Classic Personal Access Token](https://docs.github.com/en/free-pro-team@latest/github/authenticating-to-github/creating-a-personal-access-token#creating-a-token), then copy the PAT value
33
42
-[Define secret variable](https://docs.github.com/en/free-pro-team@latest/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-a-repository) named **PAT** on your repository, and paste the PAT value
0 commit comments