Severity: P3. Confidence: high. Informational.
Affected files:
.github/workflows/ci.yml:16-30, :278-280, :407-409
Evidence:
Only two of ~10 jobs declare job-level permissions; every other workflow in the repo declares an explicit block.
Impact:
Lint/test/build/e2e jobs inherit the org/repo default token scope (potentially read-write), violating least privilege; mitigated by persist-credentials: false on checkouts.
Recommendation:
Add permissions: contents: read at the workflow level; keep the two existing job-level escalations.
Verifier verdict: unverified - P3, adversarial verification skipped.
Source: docs/reviews/codebase-review-2026-06-10.md (automated multi-dimension code review, adversarially verified for P1/P2)
Severity: P3. Confidence: high. Informational.
Affected files:
.github/workflows/ci.yml:16-30,:278-280,:407-409Evidence:
Only two of ~10 jobs declare job-level permissions; every other workflow in the repo declares an explicit block.
Impact:
Lint/test/build/e2e jobs inherit the org/repo default token scope (potentially read-write), violating least privilege; mitigated by persist-credentials: false on checkouts.
Recommendation:
Add
permissions: contents: readat the workflow level; keep the two existing job-level escalations.Verifier verdict: unverified - P3, adversarial verification skipped.
Source: docs/reviews/codebase-review-2026-06-10.md (automated multi-dimension code review, adversarially verified for P1/P2)