Skip to content

ci: set least-privilege GITHUB_TOKEN permissions (SEC-847) - #592

Draft
Matt Sutkus (msuitcase) wants to merge 1 commit into
sec-842/persist-credentialsfrom
sec-842/least-privilege-permissions
Draft

Matt Sutkus (msuitcase) wants to merge 1 commit into
sec-842/persist-credentialsfrom
sec-842/least-privilege-permissions

Conversation

@msuitcase

Copy link
Copy Markdown

What

  • ci.yml: top-level permissions: contents: read; docs job gets contents: write for the gh-pages deploy.
  • release.yml: unchanged, because it already declares permissions.

Why

ci.yml had no permissions: block, so every job got the repo's default token scope, including jobs that run npm install across every dependency.

Testing note

docs only runs on master, so this PR's CI doesn't exercise it. Check the first docs run after merge.

Possible existing issue (not changed here)

release.yml sets contents: read, but AButler/upload-release-assets needs contents: write to attach files to a release. Check whether that step has been failing on recent releases.

Stack

  1. ci: don't persist GITHUB_TOKEN in checkout (SEC-847) #591: persist-credentials: false
  2. This PR (based on ci: don't persist GITHUB_TOKEN in checkout (SEC-847) #591): merge after it

Part of SEC-842.

Default the CI workflow token to read-only. Only the docs job writes to
the repo (gh-pages deploy), so it alone gets contents: write.
release.yml already declares its own permissions and is unchanged.

Refs SEC-847

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant