Skip to content

ci: change default workflow permissions to read only#3778

Merged
reubenmiller merged 1 commit intothin-edge:mainfrom
reubenmiller:chore-explicitly-set-workflow-permissions
Sep 12, 2025
Merged

ci: change default workflow permissions to read only#3778
reubenmiller merged 1 commit intothin-edge:mainfrom
reubenmiller:chore-explicitly-set-workflow-permissions

Conversation

@reubenmiller
Copy link
Copy Markdown
Contributor

Proposed changes

Addressing some suggestions from the security review (https://github.com/thin-edge/thin-edge.io/security/code-scanning) to explicitly set the Github workflow permissions in workflows to default to read only (where applicable).

Types of changes

  • Bugfix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Improvement (general improvements like code refactoring that doesn't explicitly fix a bug or add any new functionality)
  • Documentation Update (if none of the other choices apply)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

Paste Link to the issue

https://github.com/thin-edge/thin-edge.io/security/code-scanning

Checklist

  • I have read the CONTRIBUTING doc
  • I have signed the CLA (in all commits with git commit -s. You can activate automatic signing by running just prepare-dev once)
  • I ran just format as mentioned in CODING_GUIDELINES
  • I used just check as mentioned in CODING_GUIDELINES
  • I have added tests that prove my fix is effective or that my feature works
  • I have added necessary documentation (if appropriate)

Further comments

Signed-off-by: reubenmiller <reuben.d.miller@gmail.com>
@reubenmiller reubenmiller added the ci/cd Repository management and pipeline topics label Sep 11, 2025
@codecov
Copy link
Copy Markdown

codecov bot commented Sep 11, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions
Copy link
Copy Markdown
Contributor

Robot Results

✅ Passed ❌ Failed ⏭️ Skipped Total Pass % ⏱️ Duration
687 0 3 687 100 2h2m42.161556s

Copy link
Copy Markdown
Contributor

@didier-wenzek didier-wenzek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@reubenmiller reubenmiller added this pull request to the merge queue Sep 12, 2025
Merged via the queue into thin-edge:main with commit 235a9aa Sep 12, 2025
34 checks passed
@reubenmiller reubenmiller changed the title change default workflow permissions to read only ci: change default workflow permissions to read only Dec 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci/cd Repository management and pipeline topics

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants