Gh Pr Perm Audit

Security-first audit of the per-repo GitHub setting "Allow GitHub Actions to create and approve pull requests" (can_approve_pull_request_reviews) across an account. Flags repos where Actions CAN approve PRs — a required-review bypass risk (OpenSSF) — unless you intentionally allow them. Read-only: it never changes settings; it prints the exact gh command for you to run. Use when you ask: "audit Actions PR permissions", "can GitHub Actions approve PRs?", "PR approval setting check", "Actions PR 権限監査", "review-bypass チェック". DO NOT USE FOR: creating PRs, changing branch protection, or writing code.

thinkyou0714 b04c138 3 files · 18.8 KB Updated

File contents

thinkyou0714/github-flow-kit/tree/main/gh-pr-perm-audit commit b04c1382e0

Frequently asked questions

npx skillmds@latest add thinkyou0714/gh-pr-perm-audit