Repository navigation
ci(workflows): grant workflow token permissions per job - #702
Conversation
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_e0aba6f0-26ae-41bf-886f-24b03e5c00e3) |
PR Summary by QodoGrant GitHub Actions token permissions per job
AI Description
Diagram
High-Level Assessment
Files changed (6)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you |
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.
Graphify review — findings
Moves the GitHub Actions permission grants from workflow level to per-job in the ci, release, copilot-setup-steps, and smartcloud workflows, setting permissions: {} at the top so any newly added job starts with no access and must request the scopes it uses. Updates AGENTS.md and the quick-start/permissions docs to document this per-job convention and to grant smartcloud's scopes on the job rather than the workflow.
Worth a look
- Docs quick-start example omits statuses:read that the permissions table requires —
docs/introduction.mdx:96· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 27 functions depend on the 27 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 27 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit d866726, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 27 function(s) in the blast radius were not formally verified this run
|
smartcloud found 0 error(s), 2 warning(s).
This comment updates itself when you push a fix. |
f7bbdc1 to
34acd0d
Compare
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 3 advisory finding(s) below merit a look before merge.
Graphify review — findings
Sets every workflow's top-level permissions to {} and moves the required scopes onto the individual jobs, so check, copilot-setup-steps, release, and smartcloud each declare only what they use and any job added later starts with no access. Documents this per-job grant convention in AGENTS.md and updates the introduction docs' example workflow and permissions table to match.
Worth a look
- Release jobs no longer inherit contents read —
.github/workflows/release.yml:52· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
- Copilot setup job loses checkout token access —
.github/workflows/copilot-setup-steps.yml:14· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
- smartcloud job lost statuses: read permission after refactor —
docs/introduction.mdx:96· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 28 functions depend on the 28 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 28 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 81b4be4 (diverged from this PR's base — delta is approximate).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 28 function(s) in the blast radius were not formally verified this run
34acd0d to
d27ad67
Compare
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.
Graphify review — findings
Sets every workflow's top-level permissions to {} and moves the needed scopes onto individual jobs, so ci, release, copilot-setup-steps, and smartcloud each grant per-job access and any job added later starts with none. Documents this least-privilege pattern in AGENTS.md and the introduction docs, including the smartcloud example workflow and permissions table.
Worth a look
- Release workflow jobs lose default contents read token —
.github/workflows/release.yml:52· Escalate · high- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
- Copilot setup job loses repository read permission —
.github/workflows/copilot-setup-steps.yml:14· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 28 functions depend on the 28 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 28 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit 8aeaa92 (diverged from this PR's base — delta is approximate).
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 28 function(s) in the blast radius were not formally verified this run
d27ad67 to
7547f7d
Compare
CI, release, smartcloud and Copilot setup now set permissions: {} at the top
level and give each job only the scopes it uses, so a job added later starts
with no access. AGENTS.md and the introduction's example workflow follow the
same rule.
Signed-off-by: Jonathan Stevens <jonathan@resnovas.com>
7547f7d to
6bc979d
Compare
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
There was a problem hiding this comment.
Graphify reviewed this change.
Worth a look — the grounded gate found no coupling regressions or blocking issues, but 1 advisory finding(s) below merit a look before merge.
Graphify review — findings
Tightens least-privilege guidance for GitHub workflows by declaring permissions: {} at the workflow level and granting scopes per job, so any newly added job starts with zero access. Updates ci, copilot-setup-steps, and release workflows accordingly, and documents the pattern in AGENTS.md and the smartcloud quick-start/permissions docs, noting a job calling a reusable workflow inherits no more than that workflow's jobs declare.
Worth a look
- Copilot setup job loses repository read permission —
.github/workflows/copilot-setup-steps.yml:15· Escalate · medium- agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification
Impact & health
Graphify review
Impact — 26 functions depend on the 26 functions this change touches.
Health — grade A; no new coupling hotspots.
Verification — 26 functions in the blast radius were not formally verified this run (proofs are advisory here).
Health delta baseline: last indexed commit f42333b, 1 commit(s) behind this PR's base.
Gate & verification
graphify gate
PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.
Advisory (not blocking):
- verification_scope: 26 function(s) in the blast radius were not formally verified this run
ci(workflows): grant workflow token permissions per job
CI, release, smartcloud and Copilot setup now set permissions: {} at the top
level and give each job only the scopes it uses, so a job added later starts
with no access. AGENTS.md and the introduction's example workflow follow the
same rule.
Closes SMC-98
Note
Low Risk
Workflow-only hardening with no application or runtime behavior changes; mis-scoped job permissions could break CI if incorrect, but scopes mirror the previous workflow defaults.
Overview
Adopts least-privilege
GITHUB_TOKENscoping across first-party workflows: each workflow now setspermissions: {}at the top level and declares only the scopes a job needs on that job (for examplecontents: readon CI/Copilot setup, and checks/issues/PR/status scopes on the smartcloud job).release.ymldrops workflow-widecontents: readin favor of the empty default (existing per-job grants are unchanged in behavior). AGENTS.md documents this as the required pattern for new workflows, anddocs/introduction.mdxupdates the quick-start workflow example and permissions guidance so consumers grant smartcloud permissions on the job, not the workflow.Reviewed by Cursor Bugbot for commit f7bbdc1. Configure here.