Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Fine-grained permissions for job tokens is now GA

Blog post from GitLab

Post Details
Company
Date Published
Author
Alex Mark and Joe Randazzo
Word Count
335
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab 18.3 introduces fine-grained permissions for CI/CD job tokens, enhancing software supply chain security by adhering to the principle of least privilege. Previously, job tokens inherited permissions from user accounts, posing security risks if compromised. This update allows maintainers to control job token access to specific API resources like Repositories, Deployments, and more, without any default permissions. The feature supports secure automation at scale, reduces reliance on long-lived tokens, and prepares for machine-based identity, thereby reducing the attack surface. Security teams and DevOps engineers are encouraged to gradually adopt this opt-in feature by auditing current permission requirements and configuring minimal access for critical projects, ensuring secure deployment workflows without disruption.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.