Skip to content

ci: harden SCIP workflow permissions - #163

Open
grtninja wants to merge 1 commit into
sourcegraph:masterfrom
grtninja:codex/ci-harden-scip-workflow
Open

ci: harden SCIP workflow permissions#163
grtninja wants to merge 1 commit into
sourcegraph:masterfrom
grtninja:codex/ci-harden-scip-workflow

Conversation

@grtninja

Copy link
Copy Markdown

Summary

  • pin actions/checkout in .github/workflows/scip.yml to an immutable commit SHA
  • add explicit minimal permissions for the workflow token

Why

This keeps the existing SCIP upload flow intact while making the workflow a little
safer and more explicit:

  • the checkout action no longer floats on a tag
  • the workflow token is limited to contents: read
  • the change stays one-file and behavior-preserving

Related public lane: this follows the same workflow-hardening pattern as
NousResearch/hermes-agent#7646 and Aider-AI/aider#5021.

Validation

  • YAML parse of .github/workflows/scip.yml
  • git diff --check

No Go source files or runtime code paths were changed in this patch.

Pin actions/checkout in the SCIP workflow to an immutable commit SHA and trim the workflow token to contents: read. This keeps the existing upload behavior while reducing tag drift and default token scope without changing the workflow surface.

Signed-off-by: grtninja <grtninja@hotmail.com>

grtninja commented Aug 8, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-08T22:00:38Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; changed files=1
  • Checks/workflows observed at this head: no status/workflow result exposed by the current connector surface
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer/review follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer nudge; re-read this exact head/diff before any review reply.

This is a public-safe coordination receipt only. No push, merge, publication, credential, runtime, model, GPU, auth, or protected-reasoning mutation was performed or authorized by this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T04:01:16Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; changed files=1
  • Checks/workflows observed at this head: no status/workflow result exposed by the current connector surface
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer/review follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer nudge; re-read this exact head/diff before any review reply.

This is a public-safe coordination receipt only. No push, merge, publication, credential, runtime, model, GPU, auth, or protected-reasoning mutation was performed or authorized by this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T10:00:48Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; changed files=1
  • Checks/workflows observed at this head: none reported
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer/review follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T16:01:56Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; observed merge-state=see live inventory; changed files=1
  • Checks/workflows at this head: none reported
  • Review state: 0 reviews (latest none) / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T22:00:57Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; observed merge-state=see authoritative REST inventory; changed files=1
  • Checks/workflows at this head: none reported
  • Review state: 0 reviews (latest none) / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-10T04:00:32Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; observed merge-state=see authoritative REST inventory; changed files=1
  • Checks/workflows at this head: none reported
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant