Skip to content

ci: add least-privilege top-level permissions to workflows - #59

Merged
hanthor merged 2 commits into
mainfrom
fix/workflow-permissions
Oct 2, 2026
Merged

hanthor merged 2 commits into
mainfrom
fix/workflow-permissions

Conversation

@hanthor

@hanthor hanthor commented Oct 1, 2026

Copy link
Copy Markdown
Member

Adds a top-level permissions: contents: read block to workflows that lacked one (CWE-276).

  • ste.yml calls tuna-os/.github/.github/workflows/ste-lint.yml, which only checks out the repo and runs the linter, so read access is enough.

Fixes #56

🤖 Generated with Claude Code
https://claude.ai/code/session_01TexZnEN3jq4jRUi8T3zZuY

Workflows without a top-level permissions block run with the default
GITHUB_TOKEN permissions. Default to contents: read; jobs that need more
already declare job-level permissions.

Fixes #56

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TexZnEN3jq4jRUi8T3zZuY
Signed-off-by: hanthor <hanthor@users.noreply.github.com>
@hanthor
hanthor merged commit 498f53e into main Oct 2, 2026
2 checks passed
@hanthor
hanthor deleted the fix/workflow-permissions branch October 2, 2026 00:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sec-check] Missing top-level permissions block in ste.yml workflow

1 participant