Skip to content

Add permissions block#51

Open
mendral-app[bot] wants to merge 1 commit into
v2from
mendral/add-permissions-secrets-workflow
Open

Add permissions block#51
mendral-app[bot] wants to merge 1 commit into
v2from
mendral/add-permissions-secrets-workflow

Conversation

@mendral-app
Copy link
Copy Markdown
Contributor

@mendral-app mendral-app Bot commented Apr 15, 2026

Summary

  • Add explicit permissions: contents: read block to the TruffleHog secret scanning workflow (.github/workflows/secrets.yaml), following the principle of least privilege
  • This scopes the workflow to read-only access instead of relying on repository default permissions, improving auditability and reducing attack surface

Related


Note

Created by Mendral. Tag @mendral-app with feedback or questions.

Add permissions: contents: read to the TruffleHog secret scanning
workflow, following the principle of least privilege. This explicitly
scopes the workflow to read-only access instead of relying on
repository default permissions.
@mendral-app mendral-app Bot requested a review from gearnode April 15, 2026 12:07
@mendral-app mendral-app Bot marked this pull request as ready for review April 15, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants