Skip to content

ci: pin contents: read on the CI workflow#824

Merged
jan--f merged 1 commit into
prometheus:masterfrom
arpitjain099:ci/add-permissions
May 26, 2026
Merged

ci: pin contents: read on the CI workflow#824
jan--f merged 1 commit into
prometheus:masterfrom
arpitjain099:ci/add-permissions

Conversation

@arpitjain099
Copy link
Copy Markdown
Contributor

Pins the default GITHUB_TOKEN to read-only for ci.yml. Image push (Docker Hub / Quay) and release publication use their own dedicated secrets (docker_hub_login/docker_hub_password, quay_io_login/quay_io_password, and the prom-bot PAT for releases), so the default token only needs read access for the checkout. Matches the top-level pattern in the other prometheus repos.

Standard prometheus/promci pipeline. Docker Hub + Quay pushes (and any
release artifacts) use their own dedicated secrets; the default
GITHUB_TOKEN only needs read for the checkout.

Signed-off-by: arpitjain099 <arpitjain099@gmail.com>
@arpitjain099
Copy link
Copy Markdown
Contributor Author

Hi @jan--f, gentle ping on this. The PR has been open for 4 days without a review. I noticed you've been on the recent-merger side of recent merges in this repo, so I thought I'd reach out. When you have a moment, would you mind giving this a quick look? No urgency, just trying to keep it on the radar. Happy to address any feedback.

@arpitjain099
Copy link
Copy Markdown
Contributor Author

Hi, Following up on this since it's been a couple weeks. Happy to rebase or pare scope if useful. Appreciated.

Copy link
Copy Markdown
Contributor

@jan--f jan--f left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, this lgtm!

@jan--f jan--f merged commit 948db8d into prometheus:master May 26, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants