Skip to content

ci: declare least-privilege workflow-level contents: read - #20

Merged
lumirlumir merged 2 commits into
eslint:masterfrom
arpitjain099:chore/declare-workflow-perms
Jun 19, 2026
Merged

lumirlumir merged 2 commits into
eslint:masterfrom
arpitjain099:chore/declare-workflow-perms

Conversation

@arpitjain099

Copy link
Copy Markdown
Contributor

Hardens 2 workflow(s) in this repo by declaring a workflow-level permissions: contents: read. Today those workflows inherit the legacy broad read-write GITHUB_TOKEN; the read-only default reduces blast radius if any step is compromised.

I checked each file - they read the checkout and run tests/lints; no GitHub API writes (no gh pr/issue, no git push, no release/publish/comment actions). So behavior is unchanged.

Reference: the tj-actions/changed-files compromise (CVE-2025-30066) is the canonical reason to apply least-privilege defaults.

Declares an explicit workflow-level permissions: contents: read on 2 workflows that currently inherit the default broad read-write GITHUB_TOKEN. Each file was inspected and only reads the checkout; none publish, push, or write via the GitHub API. Post-CVE-2025-30066 hardening default.

Signed-off-by: Arpit Jain <[email protected]>
@eslintbot eslintbot added this to Triage May 31, 2026
@github-project-automation github-project-automation Bot moved this to Needs Triage in Triage May 31, 2026

@lumirlumir lumirlumir left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I’ve left two minor formatting suggestions for consecutive blank lines. Otherwise, LGTM.

Comment thread .github/workflows/update-readme.yml Outdated

workflow_dispatch:


Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change

Comment thread .github/workflows/add-to-triage.yml Outdated
- opened
- reopened


Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change

@lumirlumir lumirlumir moved this from Needs Triage to Implementing in Triage Jun 2, 2026
@lumirlumir

Copy link
Copy Markdown
Member

@arpitjain099 Are you still available to work on this PR?

@arpitjain099

Copy link
Copy Markdown
Contributor Author

@arpitjain099 Are you still available to work on this PR?

Sorry got busy, please give me 1hr

@arpitjain099

Copy link
Copy Markdown
Contributor Author

Done, removed the extra blank line in both files.

@lumirlumir lumirlumir left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Complete

Development

Successfully merging this pull request may close these issues.

3 participants