Skip to content

ci: tighten workflow token permissions - #273

Open
saagpatel wants to merge 1 commit into
mainfrom
codex/fleet-hardening-20261005
Open

saagpatel wants to merge 1 commit into
mainfrom
codex/fleet-hardening-20261005

Conversation

@saagpatel

Copy link
Copy Markdown
Owner

Workflow token writes were granted at workflow scope for audit issue updates, CodeQL uploads, and releases. This change defaults every workflow to contents: read, moves those writes to the audit, CodeQL, and release jobs that need them, and records the verified v0.2.14 label for the already SHA-pinned reusable proof workflow.

Validation: actionlint -ignore SC2034 .github/workflows/*.yml and git diff --check pass. SC2034 is ignored because ShellCheck cannot see the Python environment lookup in an existing audit step.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant