Skip to content

ci: scope the update dependency app token permissions#206

Open
crazy-max wants to merge 1 commit into
docker:mainfrom
crazy-max:zizmor-fixes
Open

ci: scope the update dependency app token permissions#206
crazy-max wants to merge 1 commit into
docker:mainfrom
crazy-max:zizmor-fixes

Conversation

@crazy-max
Copy link
Copy Markdown
Member

@crazy-max crazy-max commented May 20, 2026

This scopes the GitHub App token used by the dependency update workflow so it no longer inherits the full installation permission set and silence zizmor even if the GitHub App already scopes them.

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@crazy-max crazy-max requested a review from tonistiigi May 20, 2026 12:30
@crazy-max crazy-max requested a review from a team as a code owner May 20, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant