Skip to content

CI: Minimize workflow permissions and secrets#1294

Draft
hanno-becker wants to merge 1 commit into
mainfrom
ci-least-privilege
Draft

CI: Minimize workflow permissions and secrets#1294
hanno-becker wants to merge 1 commit into
mainfrom
ci-least-privilege

Conversation

@hanno-becker

Copy link
Copy Markdown
Contributor

The goal of this commit is to minimize the permissions granted to CI tasks without impacting their current functionality.

  • Remove id-token: write from those jobs that do interface with EC2: base, lint-markdown, nix, riscv, oqs/awslc integration, ct-test, baremetal, zephyr, isabelle, awslc-main. Keep it in for: ci, cbmc, slothy, pavona, scorecard.
  • Replace broad "secrets: inherit" with an explicit AWS_GITHUB_TOKEN passing.
  • Narrow the PR/merge-queue nix job to actions: read; stick with actions: write only on the main-only nix_cache path that saves the cache.

While at it, we also add tag comments to the pinned versions of donatj/symlink-check-action and zephyr actions/checkout.

The goal of this commit is to minimize the permissions granted
to CI tasks without impacting their current functionality.

- Remove `id-token: write` from those jobs that do interface with EC2:
  base, lint-markdown, nix, riscv, oqs/awslc integration, ct-test,
  baremetal, zephyr, isabelle, awslc-main. Keep it in for: ci, cbmc,
  slothy, pavona, scorecard.
- Replace broad "secrets: inherit" with an explicit AWS_GITHUB_TOKEN
  passing.
- Narrow the PR/merge-queue nix job to `actions: read`; stick with
  `actions: write` only on the main-only nix_cache path that
  saves the cache.

While at it, we also add tag comments to the pinned versions of
donatj/symlink-check-action and zephyr actions/checkout.

Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
@hanno-becker
hanno-becker requested a review from a team as a code owner July 17, 2026 05:55
@hanno-becker
hanno-becker marked this pull request as draft July 17, 2026 06:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants