Skip to content

ci: declare native release workflow permissions - #925

Merged
mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/native-release-permissions
Sep 14, 2026
Merged

mldangelo-oai merged 1 commit into
mainfrom
mdangelo/codex/native-release-permissions

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Collaborator

Summary

The native job in the npm release workflow calls a reusable workflow without declaring its token permissions. Add an explicit contents: read permission at the call site to match the native artifact workflow and its platform builds.

Changes

  • Declare contents: read on the native release job.

Testing

  • git diff --check passed.
  • Prettier check of .github/workflows/node-release.yml passed.
  • Parsed the workflow before and after the change and verified that only the native job permission map changed.
  • Recursively checked the four called native workflows: their permissions fit the caller's contents: read ceiling.

Risk and rollout

This is a workflow configuration change with no CLI or SDK API changes. The called native workflows already use contents: read. The release workflow runs on release tags or manual dispatch; local validation was static and did not invoke a release.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T17:34:56.659153Z 9c7d050 Manual request
🔒 Security Review ✅ Completed 2026-09-14T17:36:06.250225Z 9c7d050 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 9c7d0507c8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai merged commit d03eb3f into main Sep 14, 2026
52 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/native-release-permissions branch September 14, 2026 17:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant