Another small GitHub Actions setting that’s worth knowing
permissions:
contents: read
This basically tells GitHub “Give this workflow a read-only token.”
So even if something bad runs inside your CI(like a bad npm package that excute a backdoor commit), it can't use the GITHUB_TOKEN to push code, modify your repo, or mess with things.
It's a simple example of least privilege, only give a workflow the permissions it actually needs. Small line, big security win
@devwitheyob
#TechVibe #GitHubActions #DevOps
permissions:
contents: read
This basically tells GitHub “Give this workflow a read-only token.”
So even if something bad runs inside your CI(like a bad npm package that excute a backdoor commit), it can't use the GITHUB_TOKEN to push code, modify your repo, or mess with things.
It's a simple example of least privilege, only give a workflow the permissions it actually needs. Small line, big security win
@devwitheyob
#TechVibe #GitHubActions #DevOps