Narrow workflow-level permissions to contents:read and grant write access only to the specific jobs that need it (publish gets contents:write, docker gets packages:write). Reduces blast radius if a build step is compromised (P1 finding). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| codeql | ||
| ISSUE_TEMPLATE | ||
| workflows | ||
| actionlint.yaml | ||
| CODEOWNERS | ||
| dependabot.yml | ||
| label-policy.json | ||
| labeler.yml | ||
| pull_request_template.md | ||