fix: restrict GITHUB_TOKEN permissions (Scorecard alerts #26, #27) - #17
Merged
Conversation
Co-authored-by: VrilLabs <271641621+VrilLabs@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Fix code scanning alerts #26 and #27
fix: restrict GITHUB_TOKEN permissions (Scorecard alerts #26, #27)
Aug 15, 2026
VrilLabs
marked this pull request as ready for review
August 15, 2026 05:02
Contributor
There was a problem hiding this comment.
Pull request overview
This PR tightens GitHub Actions GITHUB_TOKEN permissions to address OpenSSF Scorecard Token-Permissions alerts by reducing unnecessary write scopes and making defaults explicit.
Changes:
- Add a workflow-level
permissions: read-alldefault to the Scorecard workflow. - Remove unused
security-events: writefrom the CI workflow’ssecurityjob.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| .github/workflows/scorecard.yml | Adds workflow-level default token permissions (read-all) for least-privilege alignment. |
| .github/workflows/ci.yml | Removes unnecessary security-events: write from the security job permissions. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+10
to
14
| permissions: read-all | ||
|
|
||
| jobs: | ||
| analysis: | ||
| name: Scorecard analysis |
Contributor
Author
There was a problem hiding this comment.
Added contents: read to the analysis job-level permissions block in commit Add contents: read to scorecard analysis job permissions.
Co-authored-by: VrilLabs <271641621+VrilLabs@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two Scorecard
Token-Permissionsalerts flagged overly broadGITHUB_TOKENscopes violating least-privilege.Changes
.github/workflows/ci.ymlsecurity-events: writefrom thesecurityjob — TruffleHog in this workflow does not upload SARIF, so the write permission served no purpose..github/workflows/scorecard.ymlpermissions: read-allat the workflow top-level. Job-level write permissions (security-events: write,id-token: write) remain, scoped only to the job that requires them.