ci: restrict GITHUB_TOKEN to contents:read#9
Merged
richardwooding merged 1 commit intomainfrom Apr 28, 2026
Merged
Conversation
CodeQL flagged three instances of `actions/missing-workflow-permissions` (alerts #1, #2, #3) on .github/workflows/ci.yml — one per job (lint, unit-tests, integration-tests). Without an explicit permissions block, the default GITHUB_TOKEN gets the repo-wide write permission set. All three jobs only need to read code (checkout, install deps, run ruff/mypy/pytest, upload artifacts to the run's own artifact storage). A workflow-level `permissions: contents: read` covers all three jobs and resolves all three alerts in one block. The release workflow continues to specify its own write permissions (contents: write for the GitHub Release, id-token: write for PyPI OIDC). When release.yml calls ci.yml via workflow_call, ci.yml's permissions block scopes what ci.yml's jobs can do — the caller's permissions don't propagate down — so this change does not affect release publishing. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves three CodeQL
actions/missing-workflow-permissionsalerts on.github/workflows/ci.yml(alerts #1, #2, #3 — one per job:lint,unit-tests,integration-tests).A single workflow-level
permissions: contents: readblock covers all three jobs. None of the jobs need to write back to the repo — they checkout code, install deps, runruff/mypy/pytest, and upload artifacts to the run's own artifact storage (which doesn't require additional repo-write permissions).Why this is safe for release publishing
The
release.ymlworkflow already has its own permissions block:When
release.ymlcallsci.ymlviaworkflow_call,ci.yml's permissions block scopes whatci.yml's jobs can do — the caller's permissions don't propagate down. So tightening ci.yml has no effect on release publishing.Test plan
🤖 Generated with Claude Code