Fix/token permissions id gitbot fleet 20260911 - #520
hyperpolymath wants to merge 3 commits into
Conversation
- Update CodeQL workflow to SHA-pinned actions with persist-credentials: false - Update reusable workflow pins to current standards main SHAs Generated by Mistral Vibe. Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
…-level write Apply principle of least privilege for GITHUB_TOKEN: - Change top-level permissions from 'contents: write, pull-requests: write' to read-only - Add job-level permissions to auto-merge-prs and dispatch-to-hypatia jobs This resolves Scorecard TokenPermissionsID alerts by following GitHub's recommended security practice of granting minimal top-level permissions and escalating only at the job level where needed. Generated by Mistral Vibe. Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
…ecard.yml Fixes Scorecard TokenPermissionsID alert by adding explicit contents: read permission to the analysis job's permissions block. When job-level permissions are specified, GitHub sets unspecified permissions to 'none' by default. Generated by Mistral Vibe. Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
|
Warning Review limit reachedNext included review available in 58 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Closing: the pins this PR applies are dangling — merging would break the reusable-workflow calls it touches. Evidence:
|
Pull request was closed
Summary
Closes #
Type of change
How has this been verified?
Checklist
git commit -S).SPDX-License-Identifier(code/configMPL-2.0,prose
CC-BY-SA-4.0); I did not relicense existing files.Notes for reviewers