Skip to content

ci: declare explicit GITHUB_TOKEN permissions on all workflows - #700

Merged
redhatrises merged 1 commit into
CrowdStrike:mainfrom
redhatrises:ci/tighten-workflow-permissions
Aug 6, 2026
Merged

ci: declare explicit GITHUB_TOKEN permissions on all workflows#700
redhatrises merged 1 commit into
CrowdStrike:mainfrom
redhatrises:ci/tighten-workflow-permissions

Conversation

@redhatrises

Copy link
Copy Markdown
Contributor
  • build.yml, goreleaser-check.yml: contents: read
  • codeql.yml: + security-events: write, actions: read
  • release.yml: + contents: write on the goreleaser job
  • remove docs.yml (unpinned @v1 link-check) and its orphaned mlc_config.json and wordlist.txt
  • remove harden-runner from build-artifacts.yml

- build.yml, goreleaser-check.yml: contents: read
- codeql.yml: + security-events: write, actions: read
- release.yml: + contents: write on the goreleaser job
- remove docs.yml (unpinned @v1 link-check) and its orphaned
  mlc_config.json and wordlist.txt
- remove harden-runner from build-artifacts.yml
@redhatrises
redhatrises merged commit 2c82954 into CrowdStrike:main Aug 6, 2026
8 checks passed
@redhatrises
redhatrises deleted the ci/tighten-workflow-permissions branch August 6, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants