Skip to content
This repository was archived by the owner on Aug 6, 2026. It is now read-only.

chore(ci): declare workflow-level contents: read on action-test - #8

Open
arpitjain099 wants to merge 1 commit into
slsa-framework:mainfrom
arpitjain099:chore/declare-workflow-perms
Open

chore(ci): declare workflow-level contents: read on action-test#8
arpitjain099 wants to merge 1 commit into
slsa-framework:mainfrom
arpitjain099:chore/declare-workflow-perms

Conversation

@arpitjain099

Copy link
Copy Markdown

Pins the default GITHUB_TOKEN to contents: read on .github/workflows/action-test.yml. The workflow is a manual workflow_dispatch that runs a single third-party action and prints the resulting artifact; it does not call the GitHub API.

Why

CVE-2025-30066 (March 2025 tj-actions/changed-files supply-chain compromise) exfiltrated GITHUB_TOKEN from caller workflow logs. Pinning per workflow caps runtime authority irrespective of the repo or org default, and is credited per-file by the OpenSSF Scorecard Token-Permissions check.

YAML validated locally with yaml.safe_load.

The action-test workflow is a manual workflow_dispatch that runs a single third-party action and prints the resulting artifact. It does not call any GitHub API, so capping GITHUB_TOKEN to contents: read is safe.

Motivation: CVE-2025-30066 (March 2025 tj-actions/changed-files compromise) exfiltrated GITHUB_TOKEN from caller workflow logs. Per-workflow caps bound runtime authority irrespective of repo or org default, and are credited per-file by the OpenSSF Scorecard Token-Permissions check.

YAML validated locally with yaml.safe_load.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant