Repository navigation
Scope Java CI token permissions to least privilege - #153
Merged
Merged
Conversation
The workflow granted contents/packages/id-token/security-events write to every job. Nothing in it creates a release, pushes a commit or tag, uploads SARIF, or uses OIDC, so id-token and security-events were never needed, and contents:write was only required by the dependency-graph submission step removed in 2f38800. Default to contents:read and let the docker job opt into the packages:write it needs for the GHCR login and image push. Effective GHCR permissions for that job are unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NJNZN4SSHVBz3oHYox8x1p
Contributor
There was a problem hiding this comment.
Pull request overview
This PR tightens the GitHub Actions token permissions in the Java Maven CI workflow to follow least-privilege defaults, while preserving the specific write scope needed for pushing Docker images to GHCR.
Changes:
- Reduced workflow-level
permissionsfrom multiple write scopes tocontents: read. - Added job-level
permissionsfor thedockerjob to explicitly grantpackages: write(and retaincontents: read).
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Qodana for JVMIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked Contact Qodana teamContact us at qodana-support@jetbrains.com
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to 2f38800, which removed the redundant
Update dependency graphstep.Why
maven.ymlgranted four write scopes to every job:Auditing what the workflow actually does:
id-token: write— nothing uses OIDC (no cloud login, no keyless signing). Thecache-to: type=ghainbuild-push-actionuses the Actions runtime token, not OIDC.security-events: write— nothing uploads SARIF here. Code scanning lives in the separate CodeQL and Qodana workflows, which carry their own permissions.contents: write— was only needed by the dependency-graph submission step removed in 2f38800. Nothing left creates a release, or pushes a commit or tag. (Extract versionrunsmvn versions:setlocally and never pushes.)packages: write— genuinely needed, but only bydocker, for the GHCR login and image push.Change
Default to
contents: read, and letdockeropt into thepackages: writeit needs.ci-testcontents: read(inherited)dockercontents: read,packages: write(job-level)deploycontents: read(inherited)The
dockerjob's GHCR-relevant grant is unchanged — it hadpackages: writefrom the top-level block before and has it explicitly now.Verification
actionlintis clean (same 4 pre-existing shellcheck info notes as before this change).ci-testruns on a PR —dockeranddeployare gated onrefs/tags/. So a green check here validatesci-testundercontents: read, but thedockerjob'spackages: writeis not exercised until the next release tag. Each job only reads repo contents viaactions/checkout, so the reduction tocontents: readis safe by inspection.🤖 Generated with Claude Code
https://claude.ai/code/session_01NJNZN4SSHVBz3oHYox8x1p