Skip to content

Comments

ci: set workflow permissions to read-only by default#440

Merged
Fdawgs merged 1 commit intomainfrom
ci/perms
Apr 1, 2025
Merged

ci: set workflow permissions to read-only by default#440
Fdawgs merged 1 commit intomainfrom
ci/perms

Conversation

@Fdawgs
Copy link
Member

@Fdawgs Fdawgs commented Apr 1, 2025

This PR adds permissions to the workflow and job level, making the workflows read-only by default, and allowing write access only at the job level via granular permissions. This is regularly flagged by CodeQL, Step Security, OSSF, and other security tools.
This change also allows the org to go read-only everywhere, see fastify/avvio#308 (comment)

@Fdawgs Fdawgs merged commit 2999ad0 into main Apr 1, 2025
4 checks passed
@Fdawgs Fdawgs deleted the ci/perms branch April 1, 2025 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant