Skip to content

ARO-27434 - restrict GITHUB_TOKEN permissions in workflows - #382

Merged
RadekCap merged 1 commit into
mainfrom
ARO-27434-restrict-github-token-permissions
Jun 4, 2026
Merged

RadekCap merged 1 commit into
mainfrom
ARO-27434-restrict-github-token-permissions

Conversation

@RadekCap

@RadekCap RadekCap commented Jun 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Restrict overly broad GITHUB_TOKEN permissions across 6 workflows flagged by OpenSSF Scorecard (HIGH severity alerts #65, #71, #72, #73, #74, #75).

JIRA: https://redhat.atlassian.net/browse/ARO-27434

Problem

Scorecard's Token-Permissions check flags workflows that don't declare a top-level permissions: {} block. Without it, the default GITHUB_TOKEN gets broader permissions than individual jobs need, violating the principle of least privilege.

Solution

Add permissions: {} at the workflow top level in all 6 files. For workflows that had top-level permission grants, move them down to the specific job that needs them.

Changes

File Change
pr-validation.yml Add top-level permissions: {} (job-level checks: write already correct)
create-release-stolostron.yml Add top-level permissions: {} (job-level contents: write already correct)
create-release-official.yml Add top-level permissions: {} (job-level contents: write already correct)
create-release-experimental.yml Add top-level permissions: {} (job-level contents: write already correct)
weekly-security-scan.yaml Move contents: read, security-events: write, issues: write from top-level to scan job
ffwd-branch.yaml Move contents: write from top-level to fast-forward job

Testing

  • No functional changes — all existing job-level permission grants are preserved
  • YAML syntax verified
  • Each job retains the exact permissions it had before

Ref: ARO-27434

Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated permission scoping configurations in CI/CD workflows to enforce granular access controls, restricting default permissions at the workflow level while granting specific permissions only where necessary at the job level.

Add top-level `permissions: {}` to 6 workflows flagged by OpenSSF
Scorecard (HIGH) for overly broad GITHUB_TOKEN permissions:

- pr-validation.yml: add top-level permissions: {}
  (checks: write already scoped to integration-tests job)
- create-release-stolostron.yml: add top-level permissions: {}
  (contents: write already scoped to build-and-push job)
- create-release-official.yml: add top-level permissions: {}
  (contents: write already scoped to build-and-push job)
- create-release-experimental.yml: add top-level permissions: {}
  (contents: write already scoped to build-and-push job)
- weekly-security-scan.yaml: move permissions from top-level to
  scan job; add top-level permissions: {}
- ffwd-branch.yaml: move permissions from top-level to
  fast-forward job; add top-level permissions: {}

No functional changes — all existing job-level grants are preserved.

Ref: ARO-27434

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 3, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 70ac60fc-bb2a-41d2-b7d0-2ea6786eeba5

📥 Commits

Reviewing files that changed from the base of the PR and between c5ece32 and 78b090c.

📒 Files selected for processing (6)
  • .github/workflows/create-release-experimental.yml
  • .github/workflows/create-release-official.yml
  • .github/workflows/create-release-stolostron.yml
  • .github/workflows/ffwd-branch.yaml
  • .github/workflows/pr-validation.yml
  • .github/workflows/weekly-security-scan.yaml

📝 Walkthrough

Walkthrough

Six GitHub Actions workflows are updated to implement least-privilege GitHub token permission scoping. Top-level permissions: {} declarations are added to default-restrict all unspecified permissions, with explicit job-level permission grants for only the operations each workflow requires: contents: write for release jobs, contents: read and security-events: write/issues: write for the security scan job.

Changes

Least-privilege GitHub Actions workflow permissions

Layer / File(s) Summary
Apply least-privilege permission scoping across workflows
.github/workflows/create-release-experimental.yml, .github/workflows/create-release-official.yml, .github/workflows/create-release-stolostron.yml, .github/workflows/ffwd-branch.yaml, .github/workflows/pr-validation.yml, .github/workflows/weekly-security-scan.yaml
Adds permissions: {} at the workflow level to restrict default GitHub token access across all six workflows. Job-specific permissions are explicitly declared: release workflows grant contents: write where needed, the fast-forward workflow moves contents: write to job level, and the security scan workflow grants contents: read, security-events: write, and issues: write at the job level.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

Suggested labels

lgtm

Suggested reviewers

  • mzazrivec
  • marek-veber

Poem

🐰 Six workflows, now more secure and tight,
No token sprawl, just permissions right,
Each job receives what it truly needs,
A rabbit's leap toward better deeds! 🔐

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: restricting GITHUB_TOKEN permissions across multiple workflows. It is concise and directly related to the changeset.
Description check ✅ Passed The PR description is comprehensive and well-structured, covering the problem, solution, specific file changes, and testing verification. It aligns well with the template's intent despite not following the exact template format.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ARO-27434-restrict-github-token-permissions

Comment @coderabbitai help to get the list of available commands and usage tips.

@RadekCap

RadekCap commented Jun 3, 2026

Copy link
Copy Markdown
Collaborator Author

AI Review Pipeline Summary

Category Details
Self-Review 0 findings, no commits needed
Security Review 0 findings — PR is itself a security improvement
CodeRabbit 1 round, 0 actionable findings, all 5 pre-merge checks ✅
Qodo Not configured for this repository

No changes were required — the PR is clean across all review dimensions.


🤖 Generated by /ai-review pipeline

@marek-veber marek-veber left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci

openshift-ci Bot commented Jun 4, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: marek-veber, RadekCap

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [RadekCap,marek-veber]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@RadekCap

RadekCap commented Jun 4, 2026

Copy link
Copy Markdown
Collaborator Author

/retest

@RadekCap
RadekCap merged commit 63f9bcf into main Jun 4, 2026
5 of 9 checks passed
@RadekCap
RadekCap deleted the ARO-27434-restrict-github-token-permissions branch June 4, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants