Fine-grained permissions for job tokens is now GA
Blog post from GitLab
GitLab 18.3 introduces fine-grained permissions for CI/CD job tokens, enhancing software supply chain security by adhering to the principle of least privilege. Previously, job tokens inherited permissions from user accounts, posing security risks if compromised. This update allows maintainers to control job token access to specific API resources like Repositories, Deployments, and more, without any default permissions. The feature supports secure automation at scale, reduces reliance on long-lived tokens, and prepares for machine-based identity, thereby reducing the attack surface. Security teams and DevOps engineers are encouraged to gradually adopt this opt-in feature by auditing current permission requirements and configuring minimal access for critical projects, ensuring secure deployment workflows without disruption.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.