From e864f6f564840f623d57a8f3c38c66ca2d86527b Mon Sep 17 00:00:00 2001 From: Sam Sneddon Date: Sun, 30 Aug 2026 12:41:05 -0700 Subject: [PATCH] Add explicit permissions blocks to all workflows None of the four workflow files declared a permissions block, so every job ran with the default GITHUB_TOKEN scope. What the defaults are depends on the org/repo configuration, and when the repo was created, per https://github.blog/changelog/2023-02-02-github-actions-updating-the-default-github_token-permissions-to-read-only/ By declaring these explicitly, we guarantee that the actions do not have any write access. --- .github/workflows/ci-interpreter.yml | 3 +++ .github/workflows/ci-spec.yml | 5 +++++ .github/workflows/ci-spectec.yml | 3 +++ .github/workflows/w3c-publish.yml | 3 +++ 4 files changed, 14 insertions(+) diff --git a/.github/workflows/ci-interpreter.yml b/.github/workflows/ci-interpreter.yml index f7690320ce..6cd994f652 100644 --- a/.github/workflows/ci-interpreter.yml +++ b/.github/workflows/ci-interpreter.yml @@ -12,6 +12,9 @@ on: # Allows you to run this workflow manually from the Actions tab workflow_dispatch: +permissions: + contents: read + jobs: interpreter: runs-on: ubuntu-latest diff --git a/.github/workflows/ci-spec.yml b/.github/workflows/ci-spec.yml index 0b27fd7eb8..8ac65df55a 100644 --- a/.github/workflows/ci-spec.yml +++ b/.github/workflows/ci-spec.yml @@ -12,6 +12,9 @@ on: # Allows you to run this workflow manually from the Actions tab workflow_dispatch: +permissions: + contents: read + jobs: ensure-wasm-latest: runs-on: ubuntu-latest @@ -153,6 +156,8 @@ jobs: publish-spec: runs-on: ubuntu-latest + permissions: + contents: write needs: - ensure-wasm-latest - build-core-spec diff --git a/.github/workflows/ci-spectec.yml b/.github/workflows/ci-spectec.yml index e01f2bf2d8..b7ea336f0a 100644 --- a/.github/workflows/ci-spectec.yml +++ b/.github/workflows/ci-spectec.yml @@ -12,6 +12,9 @@ on: # Allows you to run this workflow manually from the Actions tab workflow_dispatch: +permissions: + contents: read + jobs: spec-tec: runs-on: ubuntu-latest diff --git a/.github/workflows/w3c-publish.yml b/.github/workflows/w3c-publish.yml index 730633a3bc..dee2bbe8fd 100644 --- a/.github/workflows/w3c-publish.yml +++ b/.github/workflows/w3c-publish.yml @@ -32,6 +32,9 @@ env: YARN_ENABLE_IMMUTABLE_INSTALLS: false W3C_STATUS: ${{ github.event_name == 'workflow_dispatch' && inputs.w3c-status || 'CRD' }} +permissions: + contents: read + jobs: publish-to-w3c-TR: if: ${{ github.repository == 'WebAssembly/spec' }}