Skip to content

INF-09: ci.yml has no workflow-level permissions block; most jobs run with default GITHUB_TOKEN scope #1196

Description

@cristim

Severity: P3. Confidence: high. Informational.

Affected files:

  • .github/workflows/ci.yml:16-30, :278-280, :407-409

Evidence:
Only two of ~10 jobs declare job-level permissions; every other workflow in the repo declares an explicit block.

Impact:
Lint/test/build/e2e jobs inherit the org/repo default token scope (potentially read-write), violating least privilege; mitigated by persist-credentials: false on checkouts.

Recommendation:
Add permissions: contents: read at the workflow level; keep the two existing job-level escalations.

Verifier verdict: unverified - P3, adversarial verification skipped.

Source: docs/reviews/codebase-review-2026-06-10.md (automated multi-dimension code review, adversarially verified for P1/P2)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions