Skip to content

fix(ci): declare least-privilege permissions on the audit workflow - #76

Merged
albedosehen merged 1 commit into
mainfrom
fix/audit-workflow-permissions
Aug 12, 2026
Merged

albedosehen merged 1 commit into
mainfrom
fix/audit-workflow-permissions

Conversation

@albedosehen

Copy link
Copy Markdown
Collaborator

Closes the open code scanning alert actions/missing-workflow-permissions at .github/workflows/audit.yml:40.

audit.yml was the only workflow in the repository without a permissions block, so its job inherited the repository default token scope. Every step in it reads the checkout and runs npm audit against a manifest it synthesizes itself, so contents: read covers it.

Code scanning flagged actions/missing-workflow-permissions: audit.yml was the
only workflow in the repository without a permissions block, so the job
inherited the repository default token scope.

Every step only reads the checkout and runs npm against a manifest it
synthesizes itself, so contents: read is sufficient.
@albedosehen
albedosehen merged commit 0c8612d into main Aug 12, 2026
12 checks passed
@albedosehen
albedosehen deleted the fix/audit-workflow-permissions branch August 12, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant