Skip to content

Add explicit read-only permissions to CI workflow#316

Merged
JingsongLi merged 1 commit into
apache:mainfrom
arpitjain099:security/workflow-permissions-ci-readonly
May 14, 2026
Merged

Add explicit read-only permissions to CI workflow#316
JingsongLi merged 1 commit into
apache:mainfrom
arpitjain099:security/workflow-permissions-ci-readonly

Conversation

@arpitjain099
Copy link
Copy Markdown
Contributor

Summary

  • Add an explicit permissions block to .github/workflows/ci.yml.
  • Set default token scope to contents: read for CI jobs.

Why

The CI workflow only needs repository read access. Declaring this explicitly aligns with least-privilege workflow hardening.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
@arpitjain099 arpitjain099 force-pushed the security/workflow-permissions-ci-readonly branch from 2b0f6ce to c4eda93 Compare May 13, 2026 17:14
Copy link
Copy Markdown
Contributor

@JingsongLi JingsongLi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@JingsongLi JingsongLi merged commit ed3b2ca into apache:main May 14, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants