Skip to content

Conversation

@zerosnacks
Copy link
Member

@zerosnacks zerosnacks commented Sep 11, 2025

Defines per action permissions scoping, defaulting to read only

RE:

      - uses: actions/checkout@v5
        with:
          persist-credentials: false

See: actions/checkout#485

This does not yet introduce pinning to hashes, I want to find a good way to maintain this first. Apparently Dependabot has a feature for this.

@zerosnacks zerosnacks marked this pull request as ready for review September 11, 2025 14:46
@zerosnacks zerosnacks marked this pull request as draft September 11, 2025 14:56
@zerosnacks
Copy link
Member Author

zerosnacks commented Sep 11, 2025

quickly moving back to draft, want to experiment more with an even tighter set of permissions

addressed

@zerosnacks zerosnacks marked this pull request as ready for review September 15, 2025 08:33
@zerosnacks zerosnacks enabled auto-merge (squash) September 15, 2025 08:50
@zerosnacks zerosnacks changed the title chore(ci): harden workflow by scoping permissions per job chore(ci): harden workflow by setting permissions per job Sep 15, 2025
@zerosnacks zerosnacks marked this pull request as draft September 15, 2025 10:29
auto-merge was automatically disabled September 15, 2025 10:29

Pull request was converted to draft

@zerosnacks zerosnacks changed the title chore(ci): harden workflow by setting permissions per job chore(ci): harden workflow by setting default permission to read only Sep 15, 2025
@zerosnacks zerosnacks marked this pull request as ready for review September 15, 2025 10:43
@zerosnacks zerosnacks merged commit ece63a2 into main Sep 15, 2025
11 checks passed
@zerosnacks zerosnacks deleted the zerosnacks/harden-workflow branch September 15, 2025 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants