Skip to content

ci: set workflow permissions to read-only by default#6035

Merged
Fdawgs merged 1 commit intomainfrom
ci/perms
Apr 1, 2025
Merged

ci: set workflow permissions to read-only by default#6035
Fdawgs merged 1 commit intomainfrom
ci/perms

Conversation

@Fdawgs
Copy link
Copy Markdown
Member

@Fdawgs Fdawgs commented Mar 31, 2025

This PR is created by a script. Please check the changes prior to merging.

This PR adds permissions to the workflow and job level, making the workflows read-only by default, and allowing write access only at the job level via granular permissions. This is regularly flagged by CodeQL, Step Security, OSSF, and other security tools.
This change also allows the org to go read-only everywhere, see fastify/avvio#308 (comment)

@github-actions github-actions bot added the github actions Github actions related label Mar 31, 2025
@Fdawgs Fdawgs merged commit 22c716f into main Apr 1, 2025
27 checks passed
@Fdawgs Fdawgs deleted the ci/perms branch April 1, 2025 06:37
@github-actions
Copy link
Copy Markdown

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Mar 25, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

github actions Github actions related

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants