Skip to content

SA-4488 APP_SEC_PERMISSION_PR - Add permissions block to workflows#1

Open
Cmcilveen15 wants to merge 2 commits into
masterfrom
add-permissions-to-workflows_29_05_53
Open

SA-4488 APP_SEC_PERMISSION_PR - Add permissions block to workflows#1
Cmcilveen15 wants to merge 2 commits into
masterfrom
add-permissions-to-workflows_29_05_53

Conversation

@Cmcilveen15
Copy link
Copy Markdown

This PR adds a basic permissions block to workflows that do not have it.
This has been created through an automated process.
Please carefully review and asses suitability and merge.
Copilot should provide additional context to each permission block added.
This work is belongs to the following appsec ticket: https://newdaycards.atlassian.net/browse/SA-4488

Automated commit to add basic permissions block to workflow via GraphQL endpoint.
Automated commit to add basic permissions block to workflow via GraphQL endpoint.
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds explicit GitHub Actions permissions blocks to the repository’s two workflows as part of an appsec hardening effort.

Changes:

  • Adds top-level workflow token permissions to both workflows.
  • Leaves the existing LOC counting workflow logic unchanged.
  • Normalizes the final line in linux.yml.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
.github/workflows/run.yml Adds a top-level permissions block for the run workflow.
.github/workflows/linux.yml Adds a top-level permissions block for the manual LOC workflow and preserves EOF formatting.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/run.yml
Comment on lines +2 to +5
permissions:
contents: read
issues: read
pull-requests: write
Comment on lines +2 to +5
permissions:
contents: read
issues: read
pull-requests: write
Comment thread .github/workflows/run.yml
Comment on lines +2 to +5
permissions:
contents: read
issues: read
pull-requests: write
Comment on lines +2 to +5
permissions:
contents: read
issues: read
pull-requests: write
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants