Repository navigation
ci: the pull request workflow's token can read the repository and nothing else - #20
Merged
Merged
Conversation
…hing else The workflow had no permissions block, so its GITHUB_TOKEN got the repository's default grants (code scanning alert 2, actions/missing-workflow-permissions). The job checks out, builds, tests and writes a step summary: contents: read is all it needs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Fixes code scanning alert 2 (
actions/missing-workflow-permissions):.github/workflows/pr.yamlhad nopermissionsblock, so itsGITHUB_TOKENgot the repository's default grants.The job checks the code out, sets up Go, builds, tests and writes a step summary. It needs
contents: readand nothing else, so that is what the workflow now declares.release.ymlandcodeql.ymlalready declare theirs.Check
This pull request runs the changed workflow itself: if the job passes here, the permission is enough. The alert closes when CodeQL analyses
mainafter the merge.Seen while here, not changed
The coverage step pipes
go-test-coveragethroughsedandtee. The step's shell isbash -ewithoutpipefail, so the step takestee's exit status: a coverage threshold that is not met does not fail the job.defaults.run.shell: bashat the top of the workflow would turnpipefailon. Say if you want it; it is one line and a behaviour change, so I left it out of a permissions fix.🤖 Generated with Claude Code