Add explicit permissions to CI workflow jobs #24
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #23
Changes
Added explicit
permissions:blocks to all 9 jobs in ci.yml workflow.Jobs with read-only permissions
contents: readcontents: readcontents: readJobs requiring cache write
contents: read, actions: writecontents: read, actions: writecontents: read, actions: writecontents: read, actions: writecontents: read, actions: writecontents: read, actions: writeWhy
actions: write?Jobs using
Swatinem/rust-cache@v2requireactions: writepermission to save cache in the post step. Without this permission, the cache save fails with "insufficient permissions" error.Benefits
Security Impact
Before: Workflows used default permissions (potentially too broad)
After: Each job has minimal required permissions explicitly declared
Testing
actions: writeReferences