Skip to content

ci(ecosystem): restrict workflow token to read-only contents - #66

Merged
rickstaa merged 1 commit into
mainfrom
fix/ecosystem-workflow-permissions
Sep 8, 2026
Merged

ci(ecosystem): restrict workflow token to read-only contents#66
rickstaa merged 1 commit into
mainfrom
fix/ecosystem-workflow-permissions

Conversation

@rickstaa

@rickstaa rickstaa commented Sep 8, 2026

Copy link
Copy Markdown
Member

Adds an explicit permissions: contents: read block to the ecosystem URL check workflow so the GITHUB_TOKEN no longer inherits repository defaults. The job only checks out the repo and runs a script, so read-only contents is all it needs. Matches the block already used in validate-console.yml.

Fixes https://github.com/livepeer/console/security/code-scanning/2

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@rickstaa
rickstaa requested a review from adamsoffer as a code owner September 8, 2026 21:06
@vercel

vercel Bot commented Sep 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
console Ready Ready Preview Sep 8, 2026 9:08pm UTC

Request Review

@rickstaa
rickstaa merged commit 717d2d7 into main Sep 8, 2026
5 checks passed
@rickstaa
rickstaa deleted the fix/ecosystem-workflow-permissions branch September 8, 2026 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant