Skip to content

chore(ci): Harden GitHub Actions token permissions#24450

Merged
thomasqueirozb merged 5 commits intovectordotdev:masterfrom
step-security-bot:chore/GHA-061525-stepsecurity-remediation
Jan 22, 2026
Merged

chore(ci): Harden GitHub Actions token permissions#24450
thomasqueirozb merged 5 commits intovectordotdev:masterfrom
step-security-bot:chore/GHA-061525-stepsecurity-remediation

Conversation

@step-security-bot
Copy link
Contributor

Summary

This pull request is created by StepSecurity at the request of @thomasqueirozb. Please merge the Pull Request to incorporate the requested changes. Please tag @thomasqueirozb on your message if you have any questions related to the PR.

Security Fixes

Least Privileged GitHub Actions Token Permissions

The GITHUB_TOKEN is an automatically generated secret to make authenticated calls to the GitHub API. GitHub recommends setting minimum token permissions for the GITHUB_TOKEN.

Feedback

For bug reports, feature requests, and general feedback; please email support@stepsecurity.io. To create such PRs, please visit https://app.stepsecurity.io/securerepo.

Signed-off-by: StepSecurity Bot bot@stepsecurity.io

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
@step-security-bot step-security-bot requested a review from a team as a code owner January 6, 2026 15:25
@github-actions github-actions bot added the domain: ci Anything related to Vector's CI environment label Jan 6, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Jan 6, 2026

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@thomasqueirozb thomasqueirozb added the no-changelog Changes in this PR do not need user-facing explanations in the release changelog label Jan 6, 2026
@thomasqueirozb
Copy link
Contributor

recheck

@thomasqueirozb
Copy link
Contributor

recheck

@thomasqueirozb thomasqueirozb force-pushed the chore/GHA-061525-stepsecurity-remediation branch from 453598f to fddac33 Compare January 9, 2026 15:55
@thomasqueirozb thomasqueirozb force-pushed the chore/GHA-061525-stepsecurity-remediation branch from fddac33 to 3418a0a Compare January 9, 2026 15:57
@thomasqueirozb thomasqueirozb added this pull request to the merge queue Jan 22, 2026
Merged via the queue into vectordotdev:master with commit b90c21a Jan 22, 2026
50 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Jan 22, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

domain: ci Anything related to Vector's CI environment no-changelog Changes in this PR do not need user-facing explanations in the release changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants