Skip to content

build: reduce update-caps top-level workflow permission to read#1691

Merged
anderseknert merged 1 commit intoopen-policy-agent:mainfrom
timothyklee:tklee/update-caps-workflow-permissions
Sep 16, 2025
Merged

build: reduce update-caps top-level workflow permission to read#1691
anderseknert merged 1 commit intoopen-policy-agent:mainfrom
timothyklee:tklee/update-caps-workflow-permissions

Conversation

@timothyklee
Copy link
Copy Markdown
Contributor

The goal of this change is to improve the OpenSSF Scorecard score (this repo self-publishes to https://scorecard.dev/viewer/?uri=github.com/open-policy-agent/regal).

There's a pretty harsh penalty for any top-level workflow permission set to write (see Token Permissions), so this would be a good improvement to the score.

Signed-off-by: Timothy Lee <tklee@google.com>
@timothyklee timothyklee force-pushed the tklee/update-caps-workflow-permissions branch from 3497791 to d471b62 Compare September 15, 2025 18:05
Copy link
Copy Markdown
Member

@anderseknert anderseknert left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@anderseknert anderseknert merged commit e149c6d into open-policy-agent:main Sep 16, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants