Skip to content

ci: restrict GITHUB_TOKEN permissions - #3290

Merged
steebchen merged 1 commit into
mainfrom
claude/workflow-permissions-alerts-g27e24
Jul 28, 2026
Merged

steebchen merged 1 commit into
mainfrom
claude/workflow-permissions-alerts-g27e24

Conversation

@steebchen

Copy link
Copy Markdown
Member

Resolves the ten open CodeQL actions/missing-workflow-permissions alerts (#89, #81, #37, #35, #10, #7, #6, #5, #4, #3) by giving every flagged workflow job an explicit least-privilege permissions block, so GITHUB_TOKEN no longer falls back to the repository default (read-write for repos created before Feb 2023).

Changes

Workflow Alerts Change
run.yml #89 workflow-level contents: read
ci.yml #37, #6, #5, #4, #3 workflow-level contents: read (covers quality plus the four run.yml caller jobs)
e2e.yml #81, #2 workflow-level contents: read
autofix.yml #35 workflow-level contents: read
images.yml #10, #7 job-level contents: read on setup and trigger-infra-update — the file's other jobs already scope their own permissions, so this matches the existing style

Why contents: read is sufficient everywhere

Every flagged job only reads the repository; the writes in these workflows are already done with dedicated PATs rather than the workflow token:

  • autofix.yml passes token: ${{ secrets.GH_TOKEN }} to the autofix action, which is what pushes the fixup commit.
  • images.yml → trigger-infra-update dispatches into a different repository with GH_TOKEN: ${{ secrets.GH_INFRA_TOKEN }}.
  • images.yml → setup just checks out and computes an image tag.
  • e2e.yml's upload-artifact/download-artifact steps operate on same-run artifacts, which use the runtime artifact API and need no token scope.
  • run.yml sets GITHUB_TOKEN on the command step, but nothing in the build/lint/setup scripts reads it — it only serves to raise API rate limits during dependency resolution.

run.yml is a reusable workflow, so its contents: read is a subset of what ci.yml now grants and does not conflict.

Verification

  • Parsed all 11 workflow files and audited the effective permissions of every job: all are now covered at either the workflow or job level, with none missing.
  • prettier reports all five touched files unchanged (already correctly formatted).

Generated by Claude Code

Add explicit least-privilege `permissions` blocks to the workflows CodeQL
flagged under `actions/missing-workflow-permissions`, so the GITHUB_TOKEN
falls back to `contents: read` instead of inheriting repository defaults.

All flagged jobs only read the repository: pushes in autofix.yml and the
cross-repo dispatch in images.yml use dedicated PATs (GH_TOKEN /
GH_INFRA_TOKEN), and the e2e artifact steps use the same-run artifact API,
so none of them need write scopes on the workflow token.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01368Ax2WpJaKG32ySXDKKX7
Copilot AI review requested due to automatic review settings July 28, 2026 16:29
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@steebchen, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 44 seconds

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 26146c1d-4d6e-416a-808f-5e3ce982dd5f

📥 Commits

Reviewing files that changed from the base of the PR and between ec72215 and 92bab9f.

📒 Files selected for processing (5)
  • .github/workflows/autofix.yml
  • .github/workflows/ci.yml
  • .github/workflows/e2e.yml
  • .github/workflows/images.yml
  • .github/workflows/run.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/workflow-permissions-alerts-g27e24

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@steebchen
steebchen enabled auto-merge July 28, 2026 16:32
@steebchen
steebchen added this pull request to the merge queue Jul 28, 2026
Merged via the queue into main with commit 46e1aab Jul 28, 2026
37 checks passed
@steebchen
steebchen deleted the claude/workflow-permissions-alerts-g27e24 branch July 28, 2026 16:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants