security(ci): add least-privilege permissions block to e2e-wheel workflow
e2e-wheel.yml was the only workflow missing a top-level permissions: block (added during cross-OS work after PR #624 hardened the rest), so it ran with default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0. Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG W24 entry. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
c7055de5e2
commit
dab8d29645
@@ -23,6 +23,11 @@ on:
|
||||
- "src/**"
|
||||
workflow_dispatch:
|
||||
|
||||
# Least-privilege token (Scorecard Token-Permissions). This workflow only
|
||||
# reads the repo to build + smoke-test the wheel; it needs no write scopes.
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
e2e-wheel:
|
||||
name: e2e-wheel (${{ matrix.os }})
|
||||
|
||||
@@ -8,6 +8,19 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format
|
||||
|
||||
---
|
||||
|
||||
## [2026.W24] - 2026-06-08
|
||||
|
||||
### Security
|
||||
|
||||
- **Least-privilege token on the `e2e-wheel` workflow.** `e2e-wheel.yml` was the
|
||||
one CI workflow missing a top-level `permissions:` block (it was added during
|
||||
the cross-OS work after PR #624 hardened the others), so it ran with the
|
||||
default broad `GITHUB_TOKEN` scopes — dropping the OpenSSF Scorecard
|
||||
Token-Permissions check to 0. Added `permissions: contents: read`; the
|
||||
workflow only reads the repo to build and smoke-test the wheel.
|
||||
|
||||
---
|
||||
|
||||
## [2026.W23] - 2026-06-02
|
||||
|
||||
### Fixed
|
||||
|
||||
Reference in New Issue
Block a user