Skip to content

ci(workflows): grant workflow token permissions per job - #702

Merged
TGTGamer merged 1 commit into
mainfrom
claude/smc-98-job-permissions
Sep 27, 2026
Merged

TGTGamer merged 1 commit into
mainfrom
claude/smc-98-job-permissions

Conversation

@TGTGamer

@TGTGamer TGTGamer commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

ci(workflows): grant workflow token permissions per job

CI, release, smartcloud and Copilot setup now set permissions: {} at the top
level and give each job only the scopes it uses, so a job added later starts
with no access. AGENTS.md and the introduction's example workflow follow the
same rule.

Closes SMC-98


Note

Low Risk
Workflow-only hardening with no application or runtime behavior changes; mis-scoped job permissions could break CI if incorrect, but scopes mirror the previous workflow defaults.

Overview
Adopts least-privilege GITHUB_TOKEN scoping across first-party workflows: each workflow now sets permissions: {} at the top level and declares only the scopes a job needs on that job (for example contents: read on CI/Copilot setup, and checks/issues/PR/status scopes on the smartcloud job).

release.yml drops workflow-wide contents: read in favor of the empty default (existing per-job grants are unchanged in behavior). AGENTS.md documents this as the required pattern for new workflows, and docs/introduction.mdx updates the quick-start workflow example and permissions guidance so consumers grant smartcloud permissions on the job, not the workflow.

Reviewed by Cursor Bugbot for commit f7bbdc1. Configure here.

@TGTGamer
TGTGamer added this pull request to stack #703 September 27, 2026 12:22
@cursor

cursor Bot commented Sep 27, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_e0aba6f0-26ae-41bf-886f-24b03e5c00e3)

@linear-code

linear-code Bot commented Sep 27, 2026

Copy link
Copy Markdown

SMC-98

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Grant GitHub Actions token permissions per job

⚙️ Configuration changes 📝 Documentation 🕐 20-40 Minutes

Grey Divider

AI Description

• Default four workflows to no token permissions, so future jobs receive no access automatically.
• Keep existing jobs’ required scopes at job level, including release and Smartcloud permissions.
• Document the policy for contributors and in the Smartcloud example workflow.
Diagram

graph TD
  Policy["Contributor guidance"] --> Workflows["Four workflows"] --> Defaults["No default access"] --> CI(["CI and Copilot jobs"]) --> Tokens["Job-scoped tokens"]
  Defaults --> Release(["Release jobs"]) --> Tokens
  Defaults --> Smartcloud(["Smartcloud job"]) --> Tokens
Loading
High-Level Assessment

Keep the empty workflow default and explicit job grants. A workflow-level read baseline would be simpler, but would give newly added jobs access by default; the existing release jobs already follow the proposed pattern.

Files changed (6) +27 / -15

Documentation (2) +10 / -5
AGENTS.mdDocument the per-job token permission policy +2/-0

Document the per-job token permission policy

• Instructs contributors to leave workflow-level permissions empty and grant each job only its required scopes. It also addresses permission grants for reusable-workflow callers.

AGENTS.md

introduction.mdxMove example permissions to the Smartcloud job +8/-5

Move example permissions to the Smartcloud job

• Changes the example workflow to use an empty default and job-level grants. Adds guidance explaining why future jobs should receive no access by default.

docs/introduction.mdx

Other (4) +17 / -10
ci.ymlMove CI read access to the check job +4/-2

Move CI read access to the check job

• Sets workflow permissions to empty and grants contents read to the check job, preserving its access without granting it to future jobs.

.github/workflows/ci.yml

copilot-setup-steps.ymlAdd a deny-by-default Copilot setup workflow +3/-0

Add a deny-by-default Copilot setup workflow

• Adds empty workflow-level permissions. The setup job retains its existing contents read grant.

.github/workflows/copilot-setup-steps.yml

release.ymlRemove the release workflow’s default read grant +2/-2

Remove the release workflow’s default read grant

• Sets workflow permissions to empty. Existing release jobs continue to use their individually declared scopes, including the reusable-workflow call.

.github/workflows/release.yml

smartcloud.ymlScope Smartcloud permissions to its job +8/-6

Scope Smartcloud permissions to its job

• Replaces workflow-wide read and write grants with an empty default. The Smartcloud job receives the same five scopes previously granted across the workflow.

.github/workflows/smartcloud.yml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.


Graphify review — findings

Moves the GitHub Actions permission grants from workflow level to per-job in the ci, release, copilot-setup-steps, and smartcloud workflows, setting permissions: {} at the top so any newly added job starts with no access and must request the scopes it uses. Updates AGENTS.md and the quick-start/permissions docs to document this per-job convention and to grant smartcloud's scopes on the job rather than the workflow.

Worth a look

  • Docs quick-start example omits statuses:read that the permissions table requires — docs/introduction.mdx:96 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 27 functions depend on the 27 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 27 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit d866726, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 27 function(s) in the blast radius were not formally verified this run

@resnovas-smartcloud

resnovas-smartcloud Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

smartcloud found 0 error(s), 2 warning(s).

Level Rule Where Finding
warning AI-01 The AI disclosure is missing. Fill in "AI level:" with one of: none, autocomplete, chat, agent, autonomous.
warning SYNC AGENTS.md AGENTS.md removes the house:managed markers. Change it in Resnovas/.github instead.

This comment updates itself when you push a fix.

Copilot AI lite review requested due to automatic review settings September 27, 2026 12:30
@TGTGamer
TGTGamer force-pushed the claude/smc-98-job-permissions branch from f7bbdc1 to 34acd0d Compare September 27, 2026 12:30

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 3 advisory finding(s) below merit a look before merge.


Graphify review — findings

Sets every workflow's top-level permissions to {} and moves the required scopes onto the individual jobs, so check, copilot-setup-steps, release, and smartcloud each declare only what they use and any job added later starts with no access. Documents this per-job grant convention in AGENTS.md and updates the introduction docs' example workflow and permissions table to match.

Worth a look

  • Release jobs no longer inherit contents read — .github/workflows/release.yml:52 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • Copilot setup job loses checkout token access — .github/workflows/copilot-setup-steps.yml:14 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • smartcloud job lost statuses: read permission after refactor — docs/introduction.mdx:96 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 28 functions depend on the 28 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 28 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 81b4be4 (diverged from this PR's base — delta is approximate).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 28 function(s) in the blast radius were not formally verified this run

Copilot AI review requested due to automatic review settings September 27, 2026 12:37
@TGTGamer
TGTGamer force-pushed the claude/smc-98-job-permissions branch from 34acd0d to d27ad67 Compare September 27, 2026 12:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

Sets every workflow's top-level permissions to {} and moves the needed scopes onto individual jobs, so ci, release, copilot-setup-steps, and smartcloud each grant per-job access and any job added later starts with none. Documents this least-privilege pattern in AGENTS.md and the introduction docs, including the smartcloud example workflow and permissions table.

Worth a look

  • Release workflow jobs lose default contents read token — .github/workflows/release.yml:52 · Escalate · high
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • Copilot setup job loses repository read permission — .github/workflows/copilot-setup-steps.yml:14 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 28 functions depend on the 28 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 28 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit 8aeaa92 (diverged from this PR's base — delta is approximate).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 28 function(s) in the blast radius were not formally verified this run

Base automatically changed from claude/smc-97-attestations to main September 27, 2026 12:50
@TGTGamer
TGTGamer force-pushed the claude/smc-98-job-permissions branch from d27ad67 to 7547f7d Compare September 27, 2026 12:50
CI, release, smartcloud and Copilot setup now set permissions: {} at the top
level and give each job only the scopes it uses, so a job added later starts
with no access. AGENTS.md and the introduction's example workflow follow the
same rule.

Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
@TGTGamer
TGTGamer removed this pull request from stack #703 September 27, 2026 12:50
@TGTGamer
TGTGamer force-pushed the claude/smc-98-job-permissions branch from 7547f7d to 6bc979d Compare September 27, 2026 12:51
@mintlify

mintlify Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
smartcloud 🟢 Ready View Preview Sep 27, 2026, 12:51 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

@graphify-labs graphify-labs Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.


Graphify review — findings

Tightens least-privilege guidance for GitHub workflows by declaring permissions: {} at the workflow level and granting scopes per job, so any newly added job starts with zero access. Updates ci, copilot-setup-steps, and release workflows accordingly, and documents the pattern in AGENTS.md and the smartcloud quick-start/permissions docs, noting a job calling a reusable workflow inherits no more than that workflow's jobs declare.

Worth a look

  • Copilot setup job loses repository read permission — .github/workflows/copilot-setup-steps.yml:15 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 26 functions depend on the 26 functions this change touches.

Health — grade A; no new coupling hotspots.

Verification — 26 functions in the blast radius were not formally verified this run (proofs are advisory here).

Health delta baseline: last indexed commit f42333b, 1 commit(s) behind this PR's base.

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 26 function(s) in the blast radius were not formally verified this run

@TGTGamer
TGTGamer added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit 7ee506d Sep 27, 2026
28 of 29 checks passed
@TGTGamer
TGTGamer deleted the claude/smc-98-job-permissions branch September 27, 2026 13:02

This branch was successfully deployed

1 active deployment
staging - docs — 6bc979de Deployed Sep 27, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants