Skip to content

Conversation

@Fdawgs
Copy link
Member

@Fdawgs Fdawgs commented Mar 31, 2025

This PR is created by a script. Please check the changes prior to merging.

This PR adds permissions to the workflow and job level, making the workflows read-only by default, and allowing write access only at the job level via granular permissions. This is regularly flagged by CodeQL, Step Security, OSSF, and other security tools.
This change also allows the org to go read-only everywhere, see fastify/avvio#308 (comment).

This PR also sets check-latest to true, so that the actions/setup-node will check it is using the latest minor or hotfix Node version and use that instead of its cached version, this stops an issue like with 22.5.0 that introduced a regression and actions were still using that instead of 22.5.1

@github-actions
Copy link

No linked issues found. Please add the corresponding issues in the pull request description.
Use GitHub automation to close the issue when a PR is merged

@Fdawgs Fdawgs enabled auto-merge (squash) April 2, 2025 11:18
@Fdawgs Fdawgs requested review from Copilot and simoneb April 3, 2025 06:53
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates workflow configurations to enforce read-only permissions by default at the workflow level while allowing granular write access at the job level, and it updates the CI workflow to ensure the latest Node minor/hotfix version is used.

  • Added a workflow-level permissions block with "contents: read" in multiple workflow files.
  • Overridden job-level permissions to allow specific write actions where needed.
  • Modified branch filter definitions and enabled "check-latest" in the CI workflow for Node setup.

Reviewed Changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.

File Description
.github/workflows/release.yml Added workflow-level read-only permissions and job-level write overrides
.github/workflows/notify-release.yml Added workflow-level read-only permissions and set job permissions for notification job
.github/workflows/ci.yml Updated branch filters, added default read permission, and enabled check-latest option
.github/workflows/check-linked-issues.yml Added workflow-level read-only permissions and job-level permissions for linked issues
Comments suppressed due to low confidence (1)

.github/workflows/check-linked-issues.yml:13

  • The indentations of the permissions block in this file differ from the style used in the other workflow files. Please align the indentation levels consistently (e.g., child keys indented by two spaces relative to their parent) to avoid potential YAML parsing issues.
    permissions:

Copy link
Collaborator

@simoneb simoneb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Fdawgs Fdawgs merged commit 0bd4778 into main Apr 3, 2025
4 of 6 checks passed
@Fdawgs Fdawgs deleted the ci/perms branch April 3, 2025 08:47
@github-actions github-actions bot mentioned this pull request Apr 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants