Skip to content

ER: Create Epic to address GitHub permissions vulnerabilities #6649

Description

@w1ld-r

Emergent Requirement - Problem

Right now, our permissions are set to read and write but this isn't best practice. According to GitHub, "It's good security practice to set the default permission for the GITHUB_TOKEN to read access only for repository contents. The permissions can then be increased, as required, for individual jobs within the workflow file."

Screenshot of current repo settings:

screenshot_2024-04-14_115940

The GITHUB_TOKEN is automatically created and available for use in your workflows without any extra setup. It can be used for lots of things, like PR automation, workflow triggers, and accessing the GitHub API. It's probably the right token for a lot of the things we do. However, it does have some limitations, such as restricted scopes for certain actions. For more sensitive operations or when more specific permissions are needed, you may need to use custom secrets with more finely tuned scopes. If we change it to read only instead of read/write, it will have an even more limited scope.

Additionally, we are setting specific permissions in some of our workflow files (Ex: codeql.yml). In some cases this may be redundant.

This epic and its issues should determine whether or not the permissions set in workflows are needed if we change the GITHUB_TOKEN scope to read only. Or, perhaps we will need to add additional write permissions. In other words, we need an audit of our permissions across our workflows to identify where we need to restrict or expand access for each workflow.

Issue you discovered this emergent requirement in

Date discovered

2024-04-15

Did you have to do something temporarily

  • YES
  • NO

Who was involved

@gaylem

What happens if this is not addressed

If this isn't addressed, there's an increased risk of unintended changes being made to the repository, potentially leading to data loss, security breaches, or other issues.

By following best practices and setting the default permission to read access, we will reduce the potential impact of any accidental or malicious actions, as the token will only have the ability to read repository contents. This minimizes the risk of unauthorized modifications and helps ensure the overall security of our GitHub workflows.

Resources

Recommended Action Items

  • Make a new issue
  • Discuss with team
  • Let a Team Lead know

Potential solutions [draft]

We need an issue to assess how we handle permissions in GitHub. This issue needs to accomplish the following:

  1. Identify all files that use more than read permissions
  2. Create an epic
  3. Add issues to the epic to modify permissions on each file individually and test locally

We need to be sure we won't introduce any breaking changes before flipping the repo setting back to read-only

Activity

  1. added
    Feature: Refactor GHARefactoring GitHub actions to fit latest architectural norms
    size: 3ptCan be done in 13-18 hours
    EREmergent Request
    ready for dev leadIssues that tech leads or merge team members need to follow up on
    on Apr 15, 2024
  2. roslynwythe commented on Apr 18, 2024

    @roslynwythe
  3. w1ld-r commented on Apr 19, 2024

    @w1ld-r
    Author
  4. roslynwythe commented on Apr 19, 2024

    @roslynwythe
  5. ExperimentsInHonesty commented on Apr 23, 2024

    @ExperimentsInHonesty
  6. 40 remaining items

  7. removed
    DraftIssue is still in the process of being created
    on Mar 28, 2026
  8. removed
    Feature MissingThis label means that the issue needs to be linked to a precise feature label.
    ready for dev leadIssues that tech leads or merge team members need to follow up on
    on Mar 28, 2026
  9. HackforLABot commented on Mar 28, 2026

    @HackforLABot
  10. moved this from Done to Questions / In Review in P: HfLA Website: Project Boardon Mar 28, 2026
  11. moved this from Questions / In Review to New Issue Approval in P: HfLA Website: Project Boardon Mar 28, 2026
  12. added
    non-PR contributionFor wiki additions/revisions, audit spreadsheet contributions, issue-making ERs and Epics, etc.
    and removed on Mar 28, 2026
  13. added
    Feature MissingThis label means that the issue needs to be linked to a precise feature label.
    on Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Complexity: LargeComplexity: See issue making labelSee the Issue Making label to understand the issue writing difficulty levelEREmergent RequestFeature MissingThis label means that the issue needs to be linked to a precise feature label.Issue Making: Level 4Create an Epic Issue, and it's Level 2 or 3 issuesLang: GHAGitHub ActionsSkill: enhancenon-PR contributionFor wiki additions/revisions, audit spreadsheet contributions, issue-making ERs and Epics, etc.role: back end/devOpsTasks for back-end developerssize: 3ptCan be done in 13-18 hours

Type

No type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions