User Settings

User Settings is where you configure your personal credentials and defaults for how StepSecurity behaves when acting on your behalf. Settings here are scoped to you as an individual user, not to your organization or tenant.

Opening User Settings

Click your avatar in the top right of the StepSecurity app and select User Settings.

Available sections

User Settings has four sub-pages:

  • Personal Access Token: Store the GitHub Personal Access Token (PAT) that StepSecurity uses to orchestrate workflows on repositories you own

  • Workflow Templates: Point StepSecurity at a GitHub repository that contains your own custom workflow templates, so they appear alongside the built-in ones during orchestration

  • Orchestrate Options: Toggle the security controls that StepSecurity applies when it orchestrates a repository, such as restricting GITHUB_TOKEN permissions, adding step-security/harden-runner, and pinning Actions to full-length commit SHAs

  • Pull Request: Customize the title, commit message, and description that StepSecurity uses on the pull requests it opens

Last updated

Was this helpful?