Skip to content

ops: tighten workflow token permissions (Scorecard PR B)#24

Merged
amavashev merged 1 commit into
mainfrom
ops/tighten-workflow-permissions
May 2, 2026
Merged

ops: tighten workflow token permissions (Scorecard PR B)#24
amavashev merged 1 commit into
mainfrom
ops/tighten-workflow-permissions

Conversation

@amavashev
Copy link
Copy Markdown
Contributor

Same pattern as cycles-server#144. Rewrites dependabot-auto-merge.yml top-level write block into top-level read-all + per-job writes. Addresses Token-Permissions in OpenSSF Scorecard.

Same pattern as runcycles/cycles-server#144. Addresses Token-Permissions
criterion from OpenSSF Scorecard.
@amavashev amavashev merged commit 6834a02 into main May 2, 2026
@amavashev amavashev deleted the ops/tighten-workflow-permissions branch May 2, 2026 20:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant