Skip to content

Harden CI workflow permissions#124

Merged
kamui merged 1 commit into
mainfrom
harden-ci-permissions
May 23, 2026
Merged

Harden CI workflow permissions#124
kamui merged 1 commit into
mainfrom
harden-ci-permissions

Conversation

@kamui
Copy link
Copy Markdown
Owner

@kamui kamui commented May 23, 2026

Summary

  • Add least-privilege GitHub Actions token permissions
  • Pin checkout and setup-ruby actions to resolved commit SHAs

Test Plan

  • ruby -e "require 'yaml'; YAML.load_file('.github/workflows/main.yml'); puts 'workflow yaml parses'"\n- bundle exec rspec\n\n## Notes\n- Full bundle exec rake still hits existing repo-wide RuboCop offenses outside this PR.

@kamui kamui merged commit f804c18 into main May 23, 2026
13 checks passed
@kamui kamui deleted the harden-ci-permissions branch May 23, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant