From 0dbd120b2cb02e9653ec877413481917236d033b Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 23:21:25 +0000 Subject: [PATCH] ci: declare least-privilege GITHUB_TOKEN permissions Workflow- and job-level `permissions: contents: read` on ci.yml, mirroring the fix the PR #71 author landed on their branch (the two CodeQL 'Workflow does not contain permissions' alerts) and matching what ui.yml already declares. This is the only line of PR #71's 319-file, +22,662-line change set that main does not already carry in newer or identical form; see the PR body for the full re-anchor analysis. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/ci.yml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a7cef42..e6acff7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,6 +7,13 @@ on: pull_request: branches: [main] +# Least privilege for the default token, declared at the workflow level so every +# job inherits it; jobs that need more declare their own block below (this is +# what the CodeQL "Workflow does not contain permissions" rule asks for — see +# the re-anchor of PR #71's salvageable delta). +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} # A push to `main` QUEUES; a pull_request head update still cancels. @@ -43,6 +50,8 @@ jobs: repo-hygiene: name: Repo hygiene (licence · format · lint · commit) runs-on: ubuntu-24.04 + permissions: + contents: read continue-on-error: ${{ github.repository != 'hyperpolymath/MetaManifold-WebUI' }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -181,6 +190,8 @@ jobs: # for 24.04, and a runner that silently rolled to the next LTS would take that pin # with it. `runs-on` cannot read `env`, so this is a literal. runs-on: ubuntu-24.04 + permissions: + contents: read # The repository's root .Rprofile sources renv/activate.R, so R started from # the checkout auto-activates renv and rewrites the library paths. renv is a # local-development convenience; CI installs into the system library and