ARO-27434 - restrict GITHUB_TOKEN permissions in workflows - #382
Conversation
Add top-level `permissions: {}` to 6 workflows flagged by OpenSSF
Scorecard (HIGH) for overly broad GITHUB_TOKEN permissions:
- pr-validation.yml: add top-level permissions: {}
(checks: write already scoped to integration-tests job)
- create-release-stolostron.yml: add top-level permissions: {}
(contents: write already scoped to build-and-push job)
- create-release-official.yml: add top-level permissions: {}
(contents: write already scoped to build-and-push job)
- create-release-experimental.yml: add top-level permissions: {}
(contents: write already scoped to build-and-push job)
- weekly-security-scan.yaml: move permissions from top-level to
scan job; add top-level permissions: {}
- ffwd-branch.yaml: move permissions from top-level to
fast-forward job; add top-level permissions: {}
No functional changes — all existing job-level grants are preserved.
Ref: ARO-27434
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: 📒 Files selected for processing (6)
📝 WalkthroughWalkthroughSix GitHub Actions workflows are updated to implement least-privilege GitHub token permission scoping. Top-level ChangesLeast-privilege GitHub Actions workflow permissions
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
AI Review Pipeline Summary
No changes were required — the PR is clean across all review dimensions. 🤖 Generated by |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: marek-veber, RadekCap The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest |
Summary
Restrict overly broad
GITHUB_TOKENpermissions across 6 workflows flagged by OpenSSF Scorecard (HIGH severity alerts #65, #71, #72, #73, #74, #75).JIRA: https://redhat.atlassian.net/browse/ARO-27434
Problem
Scorecard's Token-Permissions check flags workflows that don't declare a top-level
permissions: {}block. Without it, the default GITHUB_TOKEN gets broader permissions than individual jobs need, violating the principle of least privilege.Solution
Add
permissions: {}at the workflow top level in all 6 files. For workflows that had top-level permission grants, move them down to the specific job that needs them.Changes
pr-validation.ymlpermissions: {}(job-levelchecks: writealready correct)create-release-stolostron.ymlpermissions: {}(job-levelcontents: writealready correct)create-release-official.ymlpermissions: {}(job-levelcontents: writealready correct)create-release-experimental.ymlpermissions: {}(job-levelcontents: writealready correct)weekly-security-scan.yamlcontents: read,security-events: write,issues: writefrom top-level toscanjobffwd-branch.yamlcontents: writefrom top-level tofast-forwardjobTesting
Ref: ARO-27434
Generated with Claude Code
Summary by CodeRabbit