Skip to content

ci: add build job to GitHub Actions workflow - #5

Merged
steebchen merged 2 commits into
mainfrom
ci/build
Apr 13, 2025
Merged

steebchen merged 2 commits into
mainfrom
ci/build

Conversation

@steebchen

Copy link
Copy Markdown
Member

Include build job for dependency installation and building.

Added a new 'build' job to the CI workflow, including steps for
checking out the code, setting up Node.js and pnpm versions,
installing dependencies, and building the project.
@steebchen
steebchen merged commit 70b5ea0 into main Apr 13, 2025
@steebchen
steebchen deleted the ci/build branch April 13, 2025 09:35
vicovaro pushed a commit to vicovaro/llmgateway that referenced this pull request Jul 28, 2026
Resolves the ten open CodeQL `actions/missing-workflow-permissions`
alerts (theopenco#89, theopenco#81, theopenco#37, theopenco#35, theopenco#10, theopenco#7, theopenco#6, theopenco#5, theopenco#4, theopenco#3) by giving every
flagged workflow job an explicit least-privilege `permissions` block, so
`GITHUB_TOKEN` no longer falls back to the repository default
(read-write for repos created before Feb 2023).

## Changes

| Workflow | Alerts | Change |
| --- | --- | --- |
| `run.yml` | theopenco#89 | workflow-level `contents: read` |
| `ci.yml` | theopenco#37, theopenco#6, theopenco#5, theopenco#4, theopenco#3 | workflow-level `contents: read`
(covers `quality` plus the four `run.yml` caller jobs) |
| `e2e.yml` | theopenco#81, #2 | workflow-level `contents: read` |
| `autofix.yml` | theopenco#35 | workflow-level `contents: read` |
| `images.yml` | theopenco#10, theopenco#7 | job-level `contents: read` on `setup` and
`trigger-infra-update` — the file's other jobs already scope their own
permissions, so this matches the existing style |

## Why `contents: read` is sufficient everywhere

Every flagged job only reads the repository; the writes in these
workflows are already done with dedicated PATs rather than the workflow
token:

- `autofix.yml` passes `token: ${{ secrets.GH_TOKEN }}` to the autofix
action, which is what pushes the fixup commit.
- `images.yml` → `trigger-infra-update` dispatches into a different
repository with `GH_TOKEN: ${{ secrets.GH_INFRA_TOKEN }}`.
- `images.yml` → `setup` just checks out and computes an image tag.
- `e2e.yml`'s `upload-artifact`/`download-artifact` steps operate on
same-run artifacts, which use the runtime artifact API and need no token
scope.
- `run.yml` sets `GITHUB_TOKEN` on the command step, but nothing in the
build/lint/setup scripts reads it — it only serves to raise API rate
limits during dependency resolution.

`run.yml` is a reusable workflow, so its `contents: read` is a subset of
what `ci.yml` now grants and does not conflict.

## Verification

- Parsed all 11 workflow files and audited the effective permissions of
every job: all are now covered at either the workflow or job level, with
none missing.
- `prettier` reports all five touched files unchanged (already correctly
formatted).

---
_Generated by [Claude
Code](https://claude.ai/code/session_01368Ax2WpJaKG32ySXDKKX7)_

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant