Skip to content

ci: set explicit read-only GITHUB_TOKEN permissions on JSON validation workflow - #3765

Open
bunlongheng wants to merge 1 commit into
DexterHuang:masterfrom
bunlongheng:ci/workflow-token-permissions
Open

ci: set explicit read-only GITHUB_TOKEN permissions on JSON validation workflow#3765
bunlongheng wants to merge 1 commit into
DexterHuang:masterfrom
bunlongheng:ci/workflow-token-permissions

Conversation

@bunlongheng

Copy link
Copy Markdown

noticed the JSON_VALIDATION workflow runs with the repo's default GITHUB_TOKEN permissions since it never declares any. the job only checks out the repo, restores the npm cache and runs the validator, so it doesn't need write access to anything. this adds a top-level permissions block with contents: read so the token handed to the run is read-only.

mostly cheap insurance: npm i executes lifecycle scripts from every transitive dependency on each PR, and the current lockfile still pins some pretty old ones (nodemon 2.x tree). if any of those ever ship a bad postinstall, a read-only token means it can't push to the repo. no behavior change for the validation itself.

@bolt-new-by-stackblitz

Copy link
Copy Markdown

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant