Skip to content

ci: set default minimum permissions#830

Merged
colinaaa merged 6 commits intolynx-family:mainfrom
colinaaa:colin/0517/permission
May 17, 2025
Merged

ci: set default minimum permissions#830
colinaaa merged 6 commits intolynx-family:mainfrom
colinaaa:colin/0517/permission

Conversation

@colinaaa
Copy link
Collaborator

Summary

Set permissions: {} for all workflows. And set required permissions for each job.

Fix: https://github.com/lynx-family/lynx-stack/security/code-scanning/124

See https://docs.zizmor.sh/audits/#excessive-permissions for more details.

Checklist

  • Tests updated (or not required).
  • Documentation updated (or not required).

@changeset-bot
Copy link

changeset-bot bot commented May 17, 2025

⚠️ No Changeset found

Latest commit: 14351bc

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

colinaaa added 4 commits May 17, 2025 21:43
This commit adds 'contents: read' and 'pull-requests: read' permissions to multiple jobs in the GitHub workflows. These permissions are necessary to ensure the workflows can access repository contents and pull request data, which is essential for their proper execution.
@codspeed-hq
Copy link

codspeed-hq bot commented May 17, 2025

CodSpeed Performance Report

Merging #830 will not alter performance

Comparing colinaaa:colin/0517/permission (14351bc) with main (1df5350)

Summary

✅ 6 untouched benchmarks

@colinaaa colinaaa merged commit 6887913 into lynx-family:main May 17, 2025
37 checks passed
@colinaaa colinaaa deleted the colin/0517/permission branch May 17, 2025 14:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant