ci: pin GITHUB_TOKEN to contents:read in all workflows#172
Conversation
|
|
Stack: security-codeql-fixes
Part of a stacked PR chain. Do not merge manually. |
67a57a1 to
1eada24
Compare
68c54c5 to
94620e0
Compare
Add top-level `permissions: contents: read` to ci.yml, build-binaries.yml, smoke-test.yml, and sign-macos.yml. Matches the defense-in-depth already applied to release.yml and the job-level pin on enforce-changeset.yml. Flagged by CodeQL (actions/missing-workflow-permissions).
94620e0 to
7bfbe2a
Compare
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughThis pull request adds a top-level Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes 🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
Summary
permissions: contents: readtoci.yml,build-binaries.yml,smoke-test.yml, andsign-macos.yml.release.ymland the job-level pin onenforce-changeset.yml.actions/missing-workflow-permissionsalerts.Test plan