Skip to content

Scope GITHUB_TOKEN in the scheduled CI workflows - #1820

Open
rajeeja wants to merge 1 commit into
mainfrom
rajeeja/ci-token-permissions
Open

rajeeja wants to merge 1 commit into
mainfrom
rajeeja/ci-token-permissions

Conversation

@rajeeja

@rajeeja rajeeja commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Closes #1819. Follow-up from #1816.

Overview

min-deps-ci.yml and upstream-dev-ci.yml had no permissions: block, so every job got the repo default, which is read/write. The test jobs — the ones running old or unreleased third-party packages — do not write anything. Only failure-issue does, and only to issues.

This adds contents: read at the top of each workflow and issues: write on failure-issue. Same pattern asv-benchmarking-pr.yml already uses.

Nothing else changes. failure-issue only calls gh issue list / edit / create, which need issues, and actions/checkout needs contents: read; both are granted.

PR Checklist

General

  • An issue is created and linked
  • Added appropriate labels
  • Filled out Overview

Testing & Benchmarking

  • [N/A] Tests — workflow-only change; YAML validated locally
  • [N/A] Benchmarks

Documentation and Examples

  • [N/A]

AI Disclosure

AI Usage: Claude

  • I have tested and take responsibility for all AI-generated content in my PR.

min-deps-ci.yml and upstream-dev-ci.yml had no permissions block, so
every job got the repo default, which is read/write. Only failure-issue
writes, and only to issues.

contents: read at the top level, issues: write on failure-issue.
Matches what asv-benchmarking-pr.yml already does.

Closes #1819
@rajeeja rajeeja added the CI Continuous Integration label Oct 9, 2026
@rajeeja
rajeeja requested a review from Sevans711 October 9, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI Continuous Integration

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Scope GITHUB_TOKEN permissions in the scheduled CI workflows

1 participant