ci: pin GITHUB_TOKEN to contents: read - #118
Open
arpitjain099 wants to merge 1 commit into
Open
Conversation
The CI workflow runs Maven build + integration tests. No GitHub API writes from the workflow, so the default GITHUB_TOKEN can be capped at contents: read. Same per-workflow least-privilege practice that came out of CVE-2025-30066 (the tj-actions/changed-files compromise leaked unspoken token scopes from caller workflow logs). Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
|
Thank you for your pull request and welcome to the Trino community. We require contributors to sign our Contributor License Agreement, and we don't seem to have you on file. Continue to work with us on the review and improvements in this PR, and submit the signed CLA to cla@trino.io. Photos, scans, or digitally-signed PDF files are all suitable. Processing may take a few days. The CLA needs to be on file before we merge your changes. For more information, see https://github.com/trinodb/cla |
Member
Author
|
CLA emailed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
ciworkflow runs the Maven build + integration tests. No GitHub API writes happen from the workflow, so the defaultGITHUB_TOKENcan be capped atcontents: readat the workflow level.Same supply-chain hardening pattern the wider GitHub Actions community adopted after CVE-2025-30066 (
tj-actions/changed-filesexfiltrated unspoken token scopes from caller workflow logs).YAML validated locally.