Skip to content

ci: declare workflow-level contents: read on check workflows#134

Open
arpitjain099 wants to merge 1 commit into
nasa:devfrom
arpitjain099:chore/declare-workflow-perms
Open

ci: declare workflow-level contents: read on check workflows#134
arpitjain099 wants to merge 1 commit into
nasa:devfrom
arpitjain099:chore/declare-workflow-perms

Conversation

@arpitjain099
Copy link
Copy Markdown

Adds workflow-level permissions: contents: read to the check workflows in this repo (format-check, codeql-build, static-analysis where present). All run pure code checks; jobs that need higher scope can still override at job level.

Post-CVE-2025-30066 (tj-actions/changed-files) hardening pattern. YAML validated locally.

All workflows just run pure checks. No GitHub API writes from workflows at workflow level. Job-level overrides for security-events on codeql remain.

Post-CVE-2025-30066 hardening pattern.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants