github / github/government.github.com
Please define actions workflow permissions
- 主要語言
- HTML
- 星號
- 2k
- 分支
- 1k
- 平均合併
- 1 天 15 小時
- 30 天內合併 PR
- 4
描述
## Workflow permissions improvement
There are **5 workflow files** that are currently lacking explicit permissions
### Affected Workflow Files
The following workflow files need permissions to be explicitly defined:
- [`.github/workflows/build.yml`](https://github.com/github/government.github.com/blob/main/.github/workflows/build.yml)
- [`.github/workflows/ensure-alphabetize.yml`](https://github.com/github/government.github.com/blob/main/.github/workflows/ensure-alphabetize.yml)
- [`.github/workflows/ensure-orgs.yml`](https://github.com/github/government.github.com/blob/main/.github/workflows/ensure-orgs.yml)
- [`.github/workflows/ensure-unique.yml`](https://github.com/github/government.github.com/blob/main/.github/workflows/ensure-unique.yml)
- [`.github/workflows/rubucop.yml`](https://github.com/github/government.github.com/blob/main/.github/workflows/rubucop.yml)
### Request
Ensure permissions are explicitly defined. Below are Copilot prompts/instructions if you would like Copilot's assistance with addressing this.
## GitHub Copilot Assignment Prompts and Context
**Task**: Add explicit permissions to GitHub Actions workflow files that are currently missing them.
**Scope**: Update the workflow files listed above to include appropriate `permissions:` blocks.
**Analysis Methodology**:
1. **Gather Current State**: Check if the workflow has any existing permissions defined
2. **Inventory Workflow Actions**:
- Actions performed directly by the workflow
- API calls made by the workflow
- External actions included via `uses:` statements
3. **Determine Required Permissions**: Map each action to its minimum required permissions
4. **Synthesize Minimal Permissions**: Create permissions block with only necessary permissions
**Requirements**:
1. Add a `permissions:` block to each workflow file that doesn't have one
2. Start with `contents: read` as the minimum permission
3. Add additional permissions only if the workflow actually needs them based on the actions it performs
4. Place the `permissions:` block at the job level or workflow level as appropriate
5. Ensure the syntax is correct and follows YAML formatting
6. Maintain existing content formatting, including indentation and comments
**Files to modify**: See the list of affected workflow files above.
**Acceptance criteria**:
- [ ] All listed workflow files have explicit permissions defined
- [ ] Permissions follow the principle of least privilege
- [ ] YAML syntax is valid
- [ ] Workflows still function correctly after changes
## Copilot Instructions:
Please create a pull request that adds appropriate `permissions:` blocks to each of the workflow files listed above. Analyze each workflow to determine the minimum permissions required based on the actions it performs, and add only those necessary permissions.
貢獻指南
研究方向
先讀取 .github/workflows 下列出的五個 workflow 檔案,並檢查每個 job 和 uses 步驟,以判定其所需的 GitHub Actions 權限。驗證 YAML,並在可用時執行儲存庫的 workflow 或設定檢查。完成的條件是每個列出的 workflow 都具有明確的最小權限 permissions 區塊,且現有的 workflow 仍能正常運作。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- github-actions
- 領域
- ci-cd, security
- Issue 類型
- 重構
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 停滯
- 描述清晰度
- 描述清楚
- 新手友好度
- 55/100