Skip to content

ci: declare workflow-level contents: read on 7 CI/lint workflows#461

Open
sundb wants to merge 1 commit into
unstablefrom
declare-workflow-perms-readonly-test
Open

ci: declare workflow-level contents: read on 7 CI/lint workflows#461
sundb wants to merge 1 commit into
unstablefrom
declare-workflow-perms-readonly-test

Conversation

@sundb
Copy link
Copy Markdown
Owner

@sundb sundb commented May 26, 2026

No description provided.

Rebased onto current main to resolve conflicts. Pins GITHUB_TOKEN to contents: read on workflows that don't write to the GitHub API.

Post-CVE-2025-30066 (tj-actions/changed-files) hardening pattern.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants