security(ci): add least-privilege permissions block to e2e-wheel workflow

e2e-wheel.yml was the only workflow missing a top-level permissions: block
(added during cross-OS work after PR #624 hardened the rest), so it ran with
default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0.
Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG
W24 entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
AIOSAI
2026-06-08 10:09:00 -07:00
co-authored by Claude Opus 4.8
parent c7055de5e2
commit dab8d29645
2 changed files with 18 additions and 0 deletions
+5
View File
@@ -23,6 +23,11 @@ on:
- "src/**"
workflow_dispatch:
# Least-privilege token (Scorecard Token-Permissions). This workflow only
# reads the repo to build + smoke-test the wheel; it needs no write scopes.
permissions:
contents: read
jobs:
e2e-wheel:
name: e2e-wheel (${{ matrix.os }})
+13
View File
@@ -8,6 +8,19 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format
---
## [2026.W24] - 2026-06-08
### Security
- **Least-privilege token on the `e2e-wheel` workflow.** `e2e-wheel.yml` was the
one CI workflow missing a top-level `permissions:` block (it was added during
the cross-OS work after PR #624 hardened the others), so it ran with the
default broad `GITHUB_TOKEN` scopes — dropping the OpenSSF Scorecard
Token-Permissions check to 0. Added `permissions: contents: read`; the
workflow only reads the repo to build and smoke-test the wheel.
---
## [2026.W23] - 2026-06-02
### Fixed