Skip to content

Restrict GitHub Actions token permissions#365

Merged
jkwill87 merged 1 commit into
mainfrom
security/code-scanning-permissions
May 29, 2026
Merged

Restrict GitHub Actions token permissions#365
jkwill87 merged 1 commit into
mainfrom
security/code-scanning-permissions

Conversation

@jkwill87

@jkwill87 jkwill87 commented May 29, 2026

Copy link
Copy Markdown
Owner

Summary

  • add explicit read-only GITHUB_TOKEN permissions to publish, pull request, and push workflows
  • grant packages: write only to Docker publish caller jobs that push to GHCR
  • remediate open CodeQL actions/missing-workflow-permissions alerts

@jkwill87 jkwill87 merged commit 9add1f6 into main May 29, 2026
5 checks passed
@jkwill87 jkwill87 deleted the security/code-scanning-permissions branch May 29, 2026 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant