From a264c4a1b9277f6427ce99f1a026a2e1055537ef Mon Sep 17 00:00:00 2001 From: Sibei Chen Date: Thu, 16 Jul 2026 15:38:09 +0800 Subject: [PATCH] Scope Java CI token permissions to least privilege The workflow granted contents/packages/id-token/security-events write to every job. Nothing in it creates a release, pushes a commit or tag, uploads SARIF, or uses OIDC, so id-token and security-events were never needed, and contents:write was only required by the dependency-graph submission step removed in 2f38800. Default to contents:read and let the docker job opt into the packages:write it needs for the GHCR login and image push. Effective GHCR permissions for that job are unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) Claude-Session: https://claude.ai/code/session_01NJNZN4SSHVBz3oHYox8x1p --- .github/workflows/maven.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/maven.yml b/.github/workflows/maven.yml index b0ddf4c..d707a23 100644 --- a/.github/workflows/maven.yml +++ b/.github/workflows/maven.yml @@ -9,11 +9,9 @@ on: pull_request: branches: ["master"] workflow_dispatch: +# Least privilege by default; jobs opt into more only where they need it. permissions: - contents: write - packages: write - id-token: write - security-events: write + contents: read jobs: ci-test: @@ -81,6 +79,10 @@ jobs: runs-on: ubuntu-latest needs: ci-test timeout-minutes: 20 + # Only this job touches GHCR (login + image push), so it is the only one granted packages:write. + permissions: + contents: read + packages: write # 🚨 only run if this workflow was triggered by a tag push (release) # workflow_dispatch reruns skip the build and re-converge the box against :latest. if: startsWith(github.ref, 'refs/tags/')