From bcc7c3159a89f2d7d7de12b4da310d2786bfdafb Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 5 Mar 2026 08:09:56 +0000 Subject: [PATCH] Secure GitHub Actions workflows with least-privilege permissions - Add `permissions: read-all` at workflow level in both main.yml and docker.yml to restrict the GITHUB_TOKEN to read-only by default - Add per-job `packages: write` and `contents: read` permissions to the docker job which needs write access to push container images Note: The @master references on Drakkar-Software/.github reusable workflows are retained as these are org-internal workflows without published version tags. https://claude.ai/code/session_01W8aBTV6r7yGD3kccARKM5v --- .github/workflows/docker.yml | 5 +++++ .github/workflows/main.yml | 2 ++ 2 files changed, 7 insertions(+) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 968ab81..e77192f 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -8,9 +8,14 @@ on: - "*" pull_request: +permissions: read-all + jobs: docker: uses: Drakkar-Software/.github/.github/workflows/docker_workflow.yml@master + permissions: + contents: read + packages: write with: distribution_name: marketmaking secrets: inherit diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index b491c9f..7a9e348 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -5,6 +5,8 @@ on: - '*' pull_request: +permissions: read-all + jobs: lint: name: ${{ matrix.os }}${{ matrix.arch }} - Python ${{ matrix.version }} - lint