diff --git a/.github/workflows/e2e-wheel.yml b/.github/workflows/e2e-wheel.yml index 727027f2..f9190a39 100644 --- a/.github/workflows/e2e-wheel.yml +++ b/.github/workflows/e2e-wheel.yml @@ -23,6 +23,11 @@ on: - "src/**" workflow_dispatch: +# Least-privilege token (Scorecard Token-Permissions). This workflow only +# reads the repo to build + smoke-test the wheel; it needs no write scopes. +permissions: + contents: read + jobs: e2e-wheel: name: e2e-wheel (${{ matrix.os }}) diff --git a/CHANGELOG.md b/CHANGELOG.md index 116b2855..d2c2e72a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,19 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format --- +## [2026.W24] - 2026-06-08 + +### Security + +- **Least-privilege token on the `e2e-wheel` workflow.** `e2e-wheel.yml` was the + one CI workflow missing a top-level `permissions:` block (it was added during + the cross-OS work after PR #624 hardened the others), so it ran with the + default broad `GITHUB_TOKEN` scopes — dropping the OpenSSF Scorecard + Token-Permissions check to 0. Added `permissions: contents: read`; the + workflow only reads the repo to build and smoke-test the wheel. + +--- + ## [2026.W23] - 2026-06-02 ### Fixed