Skip to content

Restrict workflow token and pin actions by SHA - #3

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
chore/workflow-permissions
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
chore/workflow-permissions

Conversation

@KeiaiLab-PHIL

@KeiaiLab-PHIL KeiaiLab-PHIL commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Four workflows ran with the default GITHUB_TOKEN scope; CodeQL flags
them as actions/missing-workflow-permissions. They only read the repo,
so set top-level contents: read. Jobs that publish keep their
job-level grants.

Pin every uses: to a commit SHA so a moved tag cannot change what
runs, and add Dependabot (npm, github-actions; weekly, grouped) to
keep the pins current. Run the new Python and remote MCP unit tests
in the existing smoke workflows; the remote MCP test script drops its
directory argument, which Node 22+ reads as a glob and fails on.

🤖 Generated with Claude Code

Four workflows ran with the default GITHUB_TOKEN scope; CodeQL flags
them as actions/missing-workflow-permissions. They only read the repo,
so set top-level contents: read. Jobs that publish keep their
job-level grants.

Pin every uses: to a commit SHA so a moved tag cannot change what
runs, and add Dependabot (npm, github-actions; weekly, grouped) to
keep the pins current. Run the new Python and remote MCP unit tests
in the existing smoke workflows; the remote MCP test script drops its
directory argument, which Node 22+ reads as a glob and fails on.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@eightynine01
eightynine01 force-pushed the chore/workflow-permissions branch from 017d2d1 to 32bb920 Compare October 6, 2026 02:32
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit 0a2f792 into main Oct 6, 2026
7 of 9 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the chore/workflow-permissions branch October 6, 2026 02:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant