Skip to content

Conversation

@smowton
Copy link
Contributor

@smowton smowton commented Dec 5, 2025

Added a note to the query's qhelp to note its imprecision, but also encourage usage of a permissions block regardless as a belt-and-braces measure.

Added a note to the query's qhelp to note its imprecision, but also encourage usage of a permissions block regardless as a belt-and-braces measure.
@smowton smowton requested a review from a team as a code owner December 5, 2025 12:36
Copilot AI review requested due to automatic review settings December 5, 2025 12:36
@github-actions github-actions bot added documentation Actions Analysis of GitHub Actions labels Dec 5, 2025
Copilot finished reviewing on behalf of smowton December 5, 2025 12:37
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a note to the MissingActionsPermissions.md documentation to clarify the query's limitations and encourage best practices for GitHub Actions permissions.

  • Adds a disclaimer that the query cannot check organization or repository-level token settings
  • Recommends explicit permissions definitions as a best practice even when defaults are secure
  • Provides rationale for explicit permissions: documentation of needs and protection against configuration changes

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@smowton smowton merged commit 86962c6 into main Dec 5, 2025
18 checks passed
@smowton smowton deleted the smowton/admin/document-missing-actions-permissions-shortcomings branch December 5, 2025 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Actions Analysis of GitHub Actions documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants