Skip to content

Commit a5b690e

Browse files
committed
Give the two workflows without a permissions block the least they need
sha-pinning-check.yml and update-pr-branch.yml ran with the default GITHUB_TOKEN permissions, which zizmor (excessive-permissions) and CodeQL (actions/missing-workflow-permissions) both flagged. The pin check only checks the repository out and reads its workflow files, so it gets contents: read. update-pr-branch reads and updates the pull requests with BOT_PAT, the only token the action reads, so the workflow's own token gets no permissions at all.
1 parent 5c93489 commit a5b690e

2 files changed

Lines changed: 7 additions & 0 deletions

File tree

‎.github/workflows/sha-pinning-check.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ on:
66
push:
77
branches: [ 'main' ]
88

9+
permissions:
10+
contents: read
11+
912
jobs:
1013
pin-check:
1114
runs-on: ubuntu-latest

‎.github/workflows/update-pr-branch.yml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ on:
77
# Run every hour to catch stuck PRs
88
- cron: '0 * * * *'
99

10+
# The action reads and updates the pull requests with BOT_PAT alone, so the workflow's own token needs
11+
# no permissions.
12+
permissions: {}
13+
1014
jobs:
1115
update:
1216
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)