Skip to content

Declare explicit GITHUB_TOKEN permissions in workflows - #1

Open
theharold wants to merge 1 commit into
masterfrom
ci/explicit-workflow-permissions
Open

theharold wants to merge 1 commit into
masterfrom
ci/explicit-workflow-permissions

Conversation

@theharold

Copy link
Copy Markdown

Adds a top-level permissions: block so each workflow declares the GITHUB_TOKEN scopes it needs. This is part of the org-wide switch to a read-only default token permission: workflows that declare their own scopes keep working unchanged after the switch.

Workflows: ci.yml (contents: read)

No behaviour change.

Sets least-privilege permissions on each workflow so they keep working
once the org default token permission is switched to read-only.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant