Skip to content

Consider defining explicit GitHub Actions permissions for workflows #499

@bruno-diaz-dev

Description

@bruno-diaz-dev

Hi maintainers,

While reviewing the CI workflows, I noticed that none of them define explicit permissions: and therefore rely on GitHub’s default token permissions.

GitHub recommends defining the minimum required permissions explicitly to reduce the blast radius in case of compromised workflows.

Before proposing a change, I wanted to ask:

  • Is this intentional due to specific workflow requirements?
  • Would you be open to a PR that scopes permissions to the minimum
    required for each workflow?

Happy to help with a proposal if this aligns with the project direction.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions