Skip to content

ci: scope dependabot auto-merge token permissions to the job#15

Merged
markuslf merged 1 commit into
mainfrom
chore/token-permissions
May 29, 2026
Merged

ci: scope dependabot auto-merge token permissions to the job#15
markuslf merged 1 commit into
mainfrom
chore/token-permissions

Conversation

@markuslf
Copy link
Copy Markdown
Member

Move the contents/pull-requests write permissions from the workflow top level to the auto-merge job, leaving the top level read-only. Least privilege, resolves the OSSF Scorecard Token-Permissions finding on this workflow (matches the lib/monitoring-plugins structure).

Move the contents/pull-requests write permissions from the workflow
top level to the auto-merge job, leaving the top level read-only. This
follows least privilege and resolves the OSSF Scorecard Token-Permissions
finding.
@markuslf markuslf merged commit 1296f5e into main May 29, 2026
6 checks passed
@markuslf markuslf deleted the chore/token-permissions branch May 29, 2026 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant