From 31fa23eb6a0078158283fd40ac82d8720fd4ad42 Mon Sep 17 00:00:00 2001 From: Bryan Helmkamp Date: Sat, 18 Apr 2026 01:30:43 -0400 Subject: [PATCH] chore(ci): default workflows to no permissions Start every workflow with permissions: {} and grant the minimum required per job, following Astral's defense-in-depth pattern so a newly added job can't silently inherit repo read access. Co-Authored-By: Claude Opus 4.7 (1M context) --- .github/workflows/nightly.yml | 5 +++-- .github/workflows/release.yml | 7 +++++-- .github/workflows/rust.yml | 11 +++++++++-- .github/workflows/typescript.yml | 9 +++++++-- 4 files changed, 24 insertions(+), 8 deletions(-) diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index e4954108f..fb4f8d4d5 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -9,14 +9,15 @@ concurrency: group: nightly-release cancel-in-progress: false -permissions: - contents: read +permissions: {} jobs: tag-nightly: name: Tag nightly runs-on: ubuntu-latest environment: nightly + permissions: + contents: read env: CARGO_TERM_COLOR: always steps: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aa62cdbe9..aedf19d73 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,8 +5,7 @@ on: tags: - "v*" -permissions: - contents: read +permissions: {} env: CARGO_TERM_COLOR: always @@ -17,6 +16,8 @@ jobs: verify-spa: name: Verify SPA assets runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: @@ -32,6 +33,8 @@ jobs: name: Compile (${{ matrix.target }}) needs: verify-spa runs-on: ${{ matrix.runner }} + permissions: + contents: read strategy: fail-fast: false matrix: diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index e12efe38a..80b62e31f 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -29,8 +29,7 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true -permissions: - contents: read +permissions: {} env: CARGO_TERM_COLOR: always @@ -39,6 +38,8 @@ jobs: fmt: name: Format runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: @@ -52,6 +53,8 @@ jobs: clippy: name: Clippy runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: @@ -68,6 +71,8 @@ jobs: test: name: Test (Linux) runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: @@ -83,6 +88,8 @@ jobs: name: Test (macOS) if: github.event_name == 'workflow_dispatch' runs-on: macos-15 + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: diff --git a/.github/workflows/typescript.yml b/.github/workflows/typescript.yml index a2bf4fd74..09623e14f 100644 --- a/.github/workflows/typescript.yml +++ b/.github/workflows/typescript.yml @@ -29,13 +29,14 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true -permissions: - contents: read +permissions: {} jobs: typecheck: name: Typecheck runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: @@ -47,6 +48,8 @@ jobs: test: name: Test runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: @@ -58,6 +61,8 @@ jobs: build: name: Build runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: