Skip to content

ci(validate-ecoystem-links): add job level permission#6545

Merged
Fdawgs merged 1 commit intomainfrom
ci/job-permissions
Mar 4, 2026
Merged

ci(validate-ecoystem-links): add job level permission#6545
Fdawgs merged 1 commit intomainfrom
ci/job-permissions

Conversation

@Fdawgs
Copy link
Member

@Fdawgs Fdawgs commented Mar 2, 2026

Security scanning tools often don't pick up that the top-level workflow permissions apply to all jobs.
As such this PR adds job-level permissions to make it explicit, as we have it in our other workflows.

Checklist

Signed-off-by: Frazer Smith <frazer.dev@icloud.com>
Copilot AI review requested due to automatic review settings March 2, 2026 11:32
@github-actions github-actions bot added the github actions Github actions related label Mar 2, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR makes the workflow’s least-privilege access explicit by adding job-level permissions to the existing “Validate Ecosystem Links” GitHub Actions workflow, improving clarity for security scanners that may not infer top-level permissions.

Changes:

  • Add permissions: contents: read at the validate-links job level in the validate-ecosystem-links workflow.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@Fdawgs Fdawgs merged commit cd58ed4 into main Mar 4, 2026
40 checks passed
@Fdawgs Fdawgs deleted the ci/job-permissions branch March 4, 2026 07:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github actions Github actions related

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants