Add permissions to every workflow

  • By default, Actions might have R/W to everything in repo
  • This is set in Settings > Actions at repo or org level
  • Let’s ensure we start with a "least privilege" mindset in wordsmith-web
  1. Go to org Settings > Actions > General > Workflow Permissions
  2. Ensure it’s set to Read repository contents and packages permissions
  3. Manually add permissions needed to each workflow (next slide)
  4. Permissions can be per workflow or per job (see all perms)
slide 24 (click 0 of 7)