Skip to content

fix(security): job-scope workflow token permissions - #16

Merged
Lutar, Stephen P. (stephenlutar2-hash) merged 1 commit into
mainfrom
fix/token-permissions
Jul 16, 2026
Merged

fix(security): job-scope workflow token permissions#16
Lutar, Stephen P. (stephenlutar2-hash) merged 1 commit into
mainfrom
fix/token-permissions

Conversation

@stephenlutar2-hash

Copy link
Copy Markdown
Member

Scorecard TokenPermissions (score-0 highs): top-level write grants narrowed to contents: read; each job's genuinely-required writes (SARIF upload / release assets / OIDC id-token) declared at job level. Same pattern already landed on a11oy, ouroboros, vsp-otel, szl-brand.

Scorecard TokenPermissions: top-level write grants (4 workflow file(s)) narrowed to contents:read; the writes each job actually needs (SARIF upload, releases, OIDC) move to job level.

Signed-off-by: SZL Ops <ops@szlholdings.ai>
@stephenlutar2-hash
Lutar, Stephen P. (stephenlutar2-hash) merged commit 078a825 into main Jul 16, 2026
7 checks passed
@stephenlutar2-hash
Lutar, Stephen P. (stephenlutar2-hash) deleted the fix/token-permissions branch July 16, 2026 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant