Skip to content

Restrict golangci-lint workflow token permissions - #764

Merged
stuggi merged 1 commit into
openstack-k8s-operators:mainfrom
abays:restrict-golangci-lint-token-permissions
Oct 1, 2026
Merged

stuggi merged 1 commit into
openstack-k8s-operators:mainfrom
abays:restrict-golangci-lint-token-permissions

Conversation

@abays

@abays abays commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Set contents: read as the workflow-level default for the golangci-lint workflow. Both jobs inherit read-only token permissions.

Validation

No tests were run; this change only adjusts workflow token permissions.

@abays
abays requested a review from stuggi October 1, 2026 12:12
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 5b93490a-c6f7-4254-b939-2f2790ba6c0a

📥 Commits

Reviewing files that changed from the base of the PR and between 6520773 and 339f6c1.

📒 Files selected for processing (1)
  • .github/workflows/golangci-lint.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated access settings for automated code-quality checks. This is an internal maintenance change and does not affect app features or functionality. No user-facing changes are included in this release.

Walkthrough

The golangci-lint workflow now explicitly grants the contents: read permission. It does not explicitly grant other permissions.

Changes

Lint workflow permissions

Layer / File(s) Summary
Declare workflow permissions
.github/workflows/golangci-lint.yaml
The workflow sets contents to read and declares no other permissions.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 339f6

The workflow retains its configured lint and test steps with read-only repository access, and no merge-blocking permission issue was identified.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the workflow change: it restricts the golangci-lint workflow token permissions.
Description check ✅ Passed The description accurately explains the new workflow-level contents: read-only permission and the validation performed.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@stuggi stuggi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@stuggi
stuggi merged commit 0e19abb into openstack-k8s-operators:main Oct 1, 2026
3 checks passed
@abays

abays commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/cherry-pick 18-stable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants