Skip to content

Add missing security permissions to workflows (recreated PR) #971

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 8 commits into from
May 27, 2025

Conversation

jwintel
Copy link
Contributor

@jwintel jwintel commented May 22, 2025

Description

Add permission blocks to workflow files, granting workflows only necessary permissions.

Related Issue

Scan findings # 2-11 here: https://github.com/intel/gprofiler/security/code-scanning?query=is%3Aopen+branch%3Amaster

Motivation and Context

Mitigates security vulnerabilities.

How Has This Been Tested?

  • Check if workflow still runs
  • Check if vulnerabilities are no longer detected

Checklist:

  • I have read the CONTRIBUTING document.
  • I have updated the relevant documentation. N/A
  • I have added tests for new logic. N/A

@jwintel jwintel requested a review from mlim19 May 22, 2025 21:25
@jwintel jwintel self-assigned this May 22, 2025
@jwintel jwintel marked this pull request as ready for review May 22, 2025 21:25
@jwintel jwintel merged commit 701ce06 into master May 27, 2025
201 of 215 checks passed
@jwintel jwintel deleted the jwintel-security-patch-2 branch May 27, 2025 19:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants