Repository navigation
Specify default permissions for set-pr-labels.yaml and wr-set-pr-labels.yaml #8592
Description
Activity
- addedrole: back end/devOpsTasks for back-end developersTasks for back-end developersFeature: Refactor GHARefactoring GitHub actions to fit latest architectural normsRefactoring GitHub actions to fit latest architectural normssize: 8ptCan be done in 31-48 hoursCan be done in 31-48 hoursDraftIssue is still in the process of being createdIssue is still in the process of being created
on Mar 28, 2026 - moved this to New Issue Approval in P: HfLA Website: Project Board
on Mar 28, 2026 - changed the title
[-]Specify default permissions for `set-pr-labels.yaml`[/-][+]Specify default permissions for `set-pr-labels.yaml` and `wr-set-pr-labels.yaml`[/+]on Mar 28, 2026 - added and removedDraftIssue is still in the process of being createdIssue is still in the process of being created
on Mar 30, 2026 - moved this from New Issue Approval to Ready for Prioritization in P: HfLA Website: Project Board
on Mar 30, 2026 - moved this from Ready for Prioritization to Prioritized backlog in P: HfLA Website: Project Board
on Apr 28, 2026 Hi @Tomlu60220244, thank you for taking up this issue! Hfla appreciates you :)
Do let fellow developers know about your:-
i. Availability: (When are you available to work on the issue/answer questions other programmers might have about your issue?)
ii. ETA: (When do you expect this issue to be completed?)You're awesome!
P.S. - You may not take up another issue until this issue gets merged (or closed). Thanks again :)
Availability: evenings during this week.
ETA: 8/2/2026.Hi @t-will-gillis I tested the permissions specified in this issue. With only
issues: write, the workflow failed with a 403 when applying labels to the pull request. After addingpull-requests: write, both workflows completed successfully.
Failed WR Set PR Labels run:
https://github.com/Tomlu60220244/website/actions/runs/30410163605Successful Set PR Labels run:
https://github.com/Tomlu60220244/website/actions/runs/30410978268Successful WR Set PR Labels run:
https://github.com/Tomlu60220244/website/actions/runs/30410989874Could you confirm whether
pull-requests: writeshould be added towr-set-pr-labels.yaml?Hey @Tomlu60220244 Saw your note and will look at it later today, if that's alright
Hi again @Tomlu60220244 I tested it both ways in my repo- you are correct, it does need
pull-requests: write.Great catch! When you do the PR, you can give your reasons for making the change and add me as a reviewer.
Thanks!
Thanks @t-will-gillis, I’ll add pull-requests: write to the permissions as well.
- moved this from Prioritized backlog to In progress (actively working) in P: HfLA Website: Project Board
on Aug 12, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsIn progress (actively working)
Prerequisites
Overview
We need to update the default permissions for the GitHub workflow specified in set-pr-labels.yaml and wr-set-pr-labels.yaml, so that it does not have more permissions than it needs.
Details
To align with GitHub security best practices, we want to specify the minimum required permissions for each workflow via a top-level
permissions:block to ensure that workflows only have the access they need by default.Every GitHub Actions workflow automatically receives a
GITHUB_TOKENwith a set of default repository permissions defined in the repo settings which may result in the workflow having more permissions than it needs to complete its job. By explicitly defining minimum default permissions at the workflow level, we can ensure that workflow has only the permissions it needs. Then if a job or step requires more access, those permissions can be explicitly granted using job-level permissions statements or step-level tokens (PATs).We performed an audit to identify the minimum top-level permissions required for each workflow. The goal of this and related issues is to verify that each workflow continues to function correctly with the explicitly defined permissions. This approach helps minimize unnecessary privileges and strengthen overall repository security.
For additional info, see issue #8178 and GitHub's recommendation for security best practice.
Action Items
Note that this issue involves testing GitHub Actions. See "Resources/Instructions" below for how to set up your personal environment for testing.
Refer to set-pr-labels.yaml:
on:section.jobs:insert:Next, refer to wr-set-pr-labels.yaml:
on:section.jobs:insert:Resources/Instructions