Skip to content

Conversation

Copy link

Copilot AI commented Jul 12, 2025

This PR adds minimum token permissions to all GitHub workflow files to improve security posture according to OpenSSF Scorecard recommendations.

Changes Made

Added root-level permissions to 3 workflow files:

  • auto-merge-repo-staging.yml - Added permissions: contents: read
  • auto-merge-staging-main.yml - Added permissions: contents: read
  • unit-test.yml - Added permissions: contents: read

Verified 2 already compliant workflow files:

  • fossa.yml - Already has permissions: contents: read
  • ossf-scorecard.yml - Already has permissions: read-all

Implementation Details

  • Placement: Root-level permissions blocks placed immediately after the on: block
  • Formatting: Proper blank line formatting maintained (Rule B applied - blank lines above and below)
  • Permissions: Only read permissions added as these workflows don't require write access
  • Style: No additional comments added per OpenSSF guidelines

Security Impact

These changes address the Token-Permissions check from the OpenSSF Scorecard by ensuring all workflow files have explicitly defined minimum permissions rather than using the default permissive settings.

Note

Files in auto-merge/ directories are copies from other OpenTelemetry repositories and should be updated in their source repositories, not in this sandbox repo.

Fixes #13.

Warning

Firewall rules blocked me from connecting to one or more addresses

I tried to connect to the following addresses, but was blocked by firewall rules:

  • https://storage.googleapis.com/chromium-browser-snapshots/Linux_x64/1002410/chrome-linux.zip
    • Triggering command: node install.js (http block)

If you need me to access, download, or install something from one of these locations, you can either:


💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.

Copilot AI changed the title [WIP] Add minimum token permissions for all github workflow files Add minimum token permissions for GitHub workflow files Jul 12, 2025
Copilot AI requested a review from trask July 12, 2025 22:47
Copilot finished work on behalf of trask July 12, 2025 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add minimum token permissions for all github workflow files

2 participants