Post #1590318
2026-04-09 12:55 UTC
@yossarian This is an excellent write-up. Thanks very much for sharing!
Replies (1)
-
@westonsteimel@hachyderm.io 2026-04-10 10:34
@yossarian Do you happen to know if there is already some way to enforce the empty GitHub token permissions block at the workflow level to ensure the scope is only broadened when necessary at the job level? Like a pedantic mode for zizmor excessive-permissions audit or something maybe?