Skip to content

Specify default permissions for set-pr-labels.yaml and wr-set-pr-labels.yaml #8592

Description

@t-will-gillis

Prerequisites

  1. Be a member of Hack for LA. (There are no fees to join.) If you have not joined yet, please follow the steps on our Getting Started page and attend an onboarding session.
  2. You have already read our How to Contribute to Hack for LA Guide.

Overview

We need to update the default permissions for the GitHub workflow specified in set-pr-labels.yaml and wr-set-pr-labels.yaml, so that it does not have more permissions than it needs.

Details

To align with GitHub security best practices, we want to specify the minimum required permissions for each workflow via a top-level permissions: block to ensure that workflows only have the access they need by default.

Every GitHub Actions workflow automatically receives a GITHUB_TOKEN with a set of default repository permissions defined in the repo settings which may result in the workflow having more permissions than it needs to complete its job. By explicitly defining minimum default permissions at the workflow level, we can ensure that workflow has only the permissions it needs. Then if a job or step requires more access, those permissions can be explicitly granted using job-level permissions statements or step-level tokens (PATs).

We performed an audit to identify the minimum top-level permissions required for each workflow. The goal of this and related issues is to verify that each workflow continues to function correctly with the explicitly defined permissions. This approach helps minimize unnecessary privileges and strengthen overall repository security.

For additional info, see issue #8178 and GitHub's recommendation for security best practice.

Action Items

Note that this issue involves testing GitHub Actions. See "Resources/Instructions" below for how to set up your personal environment for testing.

Refer to set-pr-labels.yaml:

  • Review the file to understand how the workflow is triggered. This is specified near the top of the YML in the on: section.
  • Near the top of the file immediately before the line jobs: insert:
      permissions:
        contents: read
        issues: read
    
  • Use clean formatting: make sure there is one line separation above and one below the permissions block.

Next, refer to wr-set-pr-labels.yaml:

  • Review the file to understand how the workflow is triggered. This is specified near the top of the YML in the on: section.
  • Near the top of the file immediately before the line jobs: insert:
      permissions:
        contents: read
        actions: read
        issues: write
    
  • Use clean formatting: make sure there is one line separation above and one below the permissions block.
  • If the workflow includes line(s) similar to the following, you will need to change these to match your situation before the workflow will run correctly:
    if: github.repository == 'hackforla/website'
    
    or
        branches:
        - 'gh-pages'
    
  • Trigger the workflow to confirm whether both run successfully with no further changes to the permissions. Note that the second workflow is triggered by completion of the first.
  • If there are errors:
    • Try to determine the nature of the error, and whether it is occurring due to a mismatched repo or branch name.
    • If you cannot track down the error, consult with the team via Slack or the weekly meetings to report your findings and get additional direction.
  • If there are no errors, submit the PR like usual. Include a link to your test log.

Resources/Instructions

Activity

  1. changed the title [-]Specify default permissions for `set-pr-labels.yaml`[/-] [+]Specify default permissions for `set-pr-labels.yaml` and `wr-set-pr-labels.yaml`[/+] on Mar 28, 2026
  2. moved this from New Issue Approval to Ready for Prioritization in P: HfLA Website: Project Boardon Mar 30, 2026
  3. moved this from Ready for Prioritization to Prioritized backlog in P: HfLA Website: Project Boardon Apr 28, 2026
  4. HackforLABot commented on Jul 28, 2026

    @HackforLABot
    Contributor

    Hi @Tomlu60220244, thank you for taking up this issue! Hfla appreciates you :)

    Do let fellow developers know about your:-
    i. Availability: (When are you available to work on the issue/answer questions other programmers might have about your issue?)
    ii. ETA: (When do you expect this issue to be completed?)

    You're awesome!

    P.S. - You may not take up another issue until this issue gets merged (or closed). Thanks again :)

  5. Tomlu60220244 commented on Jul 28, 2026

    @Tomlu60220244
    Member

    Availability: evenings during this week.
    ETA: 8/2/2026.

  6. Tomlu60220244 commented on Jul 30, 2026

    @Tomlu60220244
    Member

    Hi @t-will-gillis I tested the permissions specified in this issue. With only issues: write, the workflow failed with a 403 when applying labels to the pull request. After adding pull-requests: write, both workflows completed successfully.
    Failed WR Set PR Labels run:
    https://github.com/Tomlu60220244/website/actions/runs/30410163605

    Successful Set PR Labels run:
    https://github.com/Tomlu60220244/website/actions/runs/30410978268

    Successful WR Set PR Labels run:
    https://github.com/Tomlu60220244/website/actions/runs/30410989874

    Could you confirm whether pull-requests: write should be added to wr-set-pr-labels.yaml?

  7. t-will-gillis commented on Jul 30, 2026

    @t-will-gillis
    MemberAuthor

    Hey @Tomlu60220244 Saw your note and will look at it later today, if that's alright

  8. t-will-gillis commented on Jul 31, 2026

    @t-will-gillis
    MemberAuthor

    Hi again @Tomlu60220244 I tested it both ways in my repo- you are correct, it does need pull-requests: write.

    Great catch! When you do the PR, you can give your reasons for making the change and add me as a reviewer.

    Thanks!

  9. Tomlu60220244 commented on Jul 31, 2026

    @Tomlu60220244
    Member

    Thanks @t-will-gillis, I’ll add pull-requests: write to the permissions as well.

  10. moved this from Prioritized backlog to In progress (actively working) in P: HfLA Website: Project Boardon Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions