Problem
None of the workflows in .github/workflows/ declares a top-level permissions: block, so GITHUB_TOKEN access is controlled by repository defaults.
Evidence
pdd.yml, actionlint.yml, copyrights.yml, and the other CI workflows contain no explicit permissions policy.
Impact
Validation jobs may receive write capabilities, and a compromised third-party action could use them against the repository.
Expected behavior
Set contents: read as the default and grant extra permissions only to jobs that need them.
Problem
None of the workflows in
.github/workflows/declares a top-levelpermissions:block, soGITHUB_TOKENaccess is controlled by repository defaults.Evidence
pdd.yml,actionlint.yml,copyrights.yml, and the other CI workflows contain no explicit permissions policy.Impact
Validation jobs may receive write capabilities, and a compromised third-party action could use them against the repository.
Expected behavior
Set
contents: readas the default and grant extra permissions only to jobs that need them.