Skip to content

ci(ryo-cho): cap GITHUB_TOKEN to contents: read#1135

Open
arpitjain099 wants to merge 1 commit into
vitejs:mainfrom
arpitjain099:chore/declare-workflow-perms
Open

ci(ryo-cho): cap GITHUB_TOKEN to contents: read#1135
arpitjain099 wants to merge 1 commit into
vitejs:mainfrom
arpitjain099:chore/declare-workflow-perms

Conversation

@arpitjain099

Copy link
Copy Markdown

The Ryu-Cho-style translation-sync workflow uses a separate PAT for any issue/PR writes against docs-pt, so the default GITHUB_TOKEN isn't exercised on the write path. Workflow-level contents: read is the appropriate cap.

Post-CVE-2025-30066 (tj-actions/changed-files) hardening pattern. YAML validated locally.

Ryu-Cho-style translation-sync workflow uses a separate PAT for any issue/PR writes against the docs-pt repo, so the default GITHUB_TOKEN is not exercised on the write path. contents: read at workflow level is appropriate.

Post-CVE-2025-30066 hardening pattern. yaml.safe_load validated.

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
@netlify

netlify Bot commented May 25, 2026

Copy link
Copy Markdown

Deploy Preview for vite-docs-pt-prod ready!

Name Link
🔨 Latest commit 63ba786
🔍 Latest deploy log https://app.netlify.com/projects/vite-docs-pt-prod/deploys/6a13c37ae06e120007f9d964
😎 Deploy Preview https://deploy-preview-1135--vite-docs-pt-prod.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
Lighthouse
Lighthouse
1 paths audited
Performance: 75 (🔴 down 1 from production)
Accessibility: 85 (no change from production)
Best Practices: 92 (no change from production)
SEO: 92 (no change from production)
PWA: -
View the detailed breakdown and full score reports
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant