Skip to content

Add least-privilege permissions to CI.yaml and CD.yaml workflows #91

Description

@jhamon

Problem

Two open code-scanning alerts (actions/missing-workflow-permissions, #1 on .github/workflows/CI.yaml and #2 on .github/workflows/CD.yaml, both at line 9). Neither workflow declares a top-level permissions: block, so their GITHUB_TOKEN inherits the repo default (often read/write) instead of least privilege. docs.yml already sets permissions: contents: read and can serve as the pattern.

Proposed fix & acceptance

  • Add an explicit top-level permissions: block to CI.yaml (contents: read is sufficient — it only checks out and runs tests).
  • Add a top-level permissions: block to CD.yaml; it creates a git tag + GitHub release, so it needs contents: write (widen per-job only if needed) plus whatever the release action requires. Keep it as narrow as the publish flow allows.
  • Acceptance: both code-scanning alerts resolve (zero open), workflows still run green.

Blast radius

safe (workflow metadata only; verify CD still has permission to tag/release).

Depends on

nothing

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

maintenanceRepo maintenance sweep

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions