Skip to content

ci: add explicit permissions block to fix CodeQL alerts - #89

Merged
tonibergholm merged 1 commit into
mainfrom
fix-ci-permissions
May 22, 2026
Merged

tonibergholm merged 1 commit into
mainfrom
fix-ci-permissions

Conversation

@tonibergholm

Copy link
Copy Markdown
Member

Summary

  • Adds permissions: contents: read at the workflow level in .github/workflows/ci.yml
  • Fixes all 3 open CodeQL Medium alerts ("Workflow does not contain permissions" at lines 14, 36, 57)
  • All three jobs (rust, python, gcs) are read-only CI — they check out code, build, and run tests, so contents: read is the correct least-privilege grant

Why

GitHub Actions defaults to contents: write in some org configurations. Explicitly scoping to read prevents any job in this workflow from accidentally (or maliciously, via a compromised action) writing to the repo.

…sions alerts

Three CodeQL Medium alerts flagged that the workflow had no explicit permissions
block, leaving jobs with the default (which can be write-all on some orgs).
Pinning to contents: read at the workflow level closes all three alerts and
follows GitHub's principle-of-least-privilege guidance for CI workflows.
Copilot AI review requested due to automatic review settings May 22, 2026 14:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses GitHub CodeQL “Workflow does not contain permissions” alerts by explicitly setting a least-privilege default token scope for the CI workflow, ensuring jobs cannot write to repository contents.

Changes:

  • Add a workflow-level permissions block granting contents: read in .github/workflows/ci.yml.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@tonibergholm
tonibergholm merged commit 2a0a327 into main May 22, 2026
10 checks passed
@tonibergholm
tonibergholm deleted the fix-ci-permissions branch May 22, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants