Skip to content

ci: set workflow permissions to read-only by default#94

Merged
Fdawgs merged 1 commit into
mainfrom
ci/perms
Mar 31, 2025
Merged

ci: set workflow permissions to read-only by default#94
Fdawgs merged 1 commit into
mainfrom
ci/perms

Conversation

@Fdawgs
Copy link
Copy Markdown
Member

@Fdawgs Fdawgs commented Mar 31, 2025

This PR is created by a script. Please check the changes prior to merging.

This PR adds permissions to the workflow and job level, making the workflows read-only by default, and allowing write access only at the job level via granular permissions. This is regularly flagged by CodeQL, Step Security, OSSF, and other security tools.
This change also allows the org to go read-only everywhere, see fastify/avvio#308 (comment)

@Fdawgs Fdawgs merged commit 897da57 into main Mar 31, 2025
@Fdawgs Fdawgs deleted the ci/perms branch March 31, 2025 14:33
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 1, 2026

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions Bot locked as resolved and limited conversation to collaborators May 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant