Elektrine lite

← Feed

@westonsteimel@hachyderm.io

Post #1590319

2026-04-10 10:34 UTC

@yossarian Do you happen to know if there is already some way to enforce the empty GitHub token permissions block at the workflow level to ensure the scope is only broadened when necessary at the job level? Like a pedantic mode for zizmor excessive-permissions audit or something maybe?

Replies (1)

  • @yossarian@infosec.exchange 2026-04-10 12:29

    @westonsteimel hmm, like something where zizmor warns you to always explicitly put `permissions: {}`, even if all jobs are already down-scoped? That’s something I’d consider adding as a pedantic or auditor finding to zizmor, but I’m not aware of anything else that does that

    Open ##1590320