Skip to content

Harden repository security: least-privilege workflows and CODEOWNERS - #92

Merged
snecklifter merged 1 commit into
mainfrom
security-hardening
Jul 22, 2026
Merged

snecklifter merged 1 commit into
mainfrom
security-hardening

Conversation

@snecklifter

Copy link
Copy Markdown
Contributor

Summary

  • Add explicit permissions: contents: read to all three CI workflow files, following the principle of least privilege
  • Add .github/CODEOWNERS to enforce review routing through @snecklifter

Companion repo-level changes (already applied)

  • Default workflow token permissions changed from write to read
  • can_approve_pull_request_reviews disabled for the GITHUB_TOKEN
  • Secret scanning and push protection enabled

Test plan

  • Verify CI workflows still pass with explicit read-only permissions
  • Verify CODEOWNERS triggers review requests on new PRs

🤖 Generated with Claude Code

Add explicit `permissions: contents: read` to all CI workflows so they
don't inherit the (now restricted) repo-wide default silently. Add a
CODEOWNERS file to enforce review routing through the maintainer.

Companion repo-level changes (already applied via API):
- Default workflow token permissions set to read-only
- Secret scanning and push protection enabled

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@snecklifter snecklifter self-assigned this Jul 22, 2026
@snecklifter
snecklifter merged commit 207e656 into main Jul 22, 2026
5 checks passed
@snecklifter
snecklifter deleted the security-hardening branch September 18, 2026 20:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant