Skip to content

Comments

ci: set workflow permissions to read-only by default#210

Merged
galvez merged 1 commit intodevfrom
ci/perms
Mar 31, 2025
Merged

ci: set workflow permissions to read-only by default#210
galvez merged 1 commit intodevfrom
ci/perms

Conversation

@Fdawgs
Copy link
Member

@Fdawgs Fdawgs commented Mar 31, 2025

This PR is created by a script. Please check the changes prior to merging.

This PR adds permissions to the workflow and job level, making the workflows read-only by default, and allowing write access only at the job level via granular permissions. This is regularly flagged by CodeQL, Step Security, OSSF, and other security tools.
This change also allows the org to go read-only everywhere, see fastify/avvio#308 (comment)

@netlify
Copy link

netlify bot commented Mar 31, 2025

Deploy Preview for agitated-mahavira-26f8f9 canceled.

Name Link
🔨 Latest commit fdf48f3
🔍 Latest deploy log https://app.netlify.com/sites/agitated-mahavira-26f8f9/deploys/67eaa6244a456d000875ade1

Copy link
Member

@galvez galvez left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@galvez galvez merged commit fc1e44e into dev Mar 31, 2025
6 of 7 checks passed
@Fdawgs Fdawgs deleted the ci/perms branch March 31, 2025 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants