Skip to content

ci: the pull request workflow's token can read the repository and nothing else - #20

Merged
christiangda merged 1 commit into
mainfrom
ci/pr-workflow-least-privilege
Oct 4, 2026
Merged

christiangda merged 1 commit into
mainfrom
ci/pr-workflow-least-privilege

Conversation

@christiangda

Copy link
Copy Markdown
Contributor

What

Fixes code scanning alert 2 (actions/missing-workflow-permissions): .github/workflows/pr.yaml had no permissions block, so its GITHUB_TOKEN got the repository's default grants.

The job checks the code out, sets up Go, builds, tests and writes a step summary. It needs contents: read and nothing else, so that is what the workflow now declares. release.yml and codeql.yml already declare theirs.

Check

This pull request runs the changed workflow itself: if the job passes here, the permission is enough. The alert closes when CodeQL analyses main after the merge.

Seen while here, not changed

The coverage step pipes go-test-coverage through sed and tee. The step's shell is bash -e without pipefail, so the step takes tee's exit status: a coverage threshold that is not met does not fail the job. defaults.run.shell: bash at the top of the workflow would turn pipefail on. Say if you want it; it is one line and a behaviour change, so I left it out of a permissions fix.

🤖 Generated with Claude Code

…hing else

The workflow had no permissions block, so its GITHUB_TOKEN got the
repository's default grants (code scanning alert 2,
actions/missing-workflow-permissions). The job checks out, builds, tests and
writes a step summary: contents: read is all it needs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@christiangda
christiangda merged commit f493601 into main Oct 4, 2026
1 check passed
@christiangda
christiangda deleted the ci/pr-workflow-least-privilege branch October 4, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant