Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
ci: drop the workflow token's write access and persistence
Review flagged that `npm test` runs pull-request-authored code after
checkout persists its credentials. The repository default is already
read-only, so this closes the conditional rather than an open hole -- but
the default is a setting somebody can change, and the workflow should not
depend on it.

Co-Authored-By: Claude Opus 5 <[email protected]>
  • Loading branch information
mark-brannan and claude committed Aug 26, 2026
commit f7d83060254cdc37693f4f61ee812112088c2a2e
7 changes: 7 additions & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@ name: test
on:
push: { branches: [main] }
pull_request:

# The tests run pull-request-authored code. Nothing here needs to write to the
# repository, and the checkout's token should not outlive the step.
permissions:
contents: read

jobs:
test:
runs-on: ubuntu-latest
Expand All @@ -10,6 +16,7 @@ jobs:
node: ['20', '22', '24']
steps:
- uses: actions/checkout@v4
with: { persist-credentials: false }
- uses: actions/setup-node@v4
with: { node-version: '${{ matrix.node }}' }
# The one dependency is `ampacity`, which is data and ships no code.
Expand Down
Loading