Declare read-only permissions on the status-check workflow
CodeQL flagged the new static-analysis job for relying on the repository's default GITHUB_TOKEN scope. Fair, and the repo already holds the opposite opinion elsewhere: build.yml's release job spells out contents: write with a comment saying the token's reach should be visible at the point of use. Set at workflow level rather than on the one job that was flagged, because none of these four write anything -- they read the code, build it and attach reports. It also means a repository default that widens later cannot quietly widen these jobs with it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -14,6 +14,14 @@ concurrency:
|
||||
# owner can repoint v4 at new code, so a tag reference is an open invitation to run
|
||||
# whatever that repository contains tomorrow. The trailing comment records which
|
||||
# release each hash corresponds to, since a bare hash is unreadable.
|
||||
# Nothing here writes: these jobs read the code, build it and attach reports. Declared
|
||||
# explicitly rather than inherited from the repository default, for the same reason the
|
||||
# action SHAs above are pinned -- the token's reach should be readable here, and a default
|
||||
# that widens later should not silently widen these jobs with it. build.yml's release job
|
||||
# makes the opposite declaration for the same reason.
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
GRADLE_CACHE_PATHS: |
|
||||
~/.gradle/caches
|
||||
|
||||
Reference in New Issue
Block a user