From 46468c96021cad8b67bd8ec7f42473b02fd191a1 Mon Sep 17 00:00:00 2001 From: maziggy Date: Fri, 1 May 2026 11:49:46 +0200 Subject: [PATCH] Updated .github/workflows/cleanup-ghcr.yml --- .github/workflows/cleanup-ghcr.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/cleanup-ghcr.yml b/.github/workflows/cleanup-ghcr.yml index 1b82ddd40..4cc22554a 100644 --- a/.github/workflows/cleanup-ghcr.yml +++ b/.github/workflows/cleanup-ghcr.yml @@ -19,6 +19,12 @@ on: type: boolean default: false +# This workflow authenticates exclusively via GHCR_CLEANUP_TOKEN (a classic PAT) +# and never reads/writes via the default GITHUB_TOKEN. Strip every permission +# from the GITHUB_TOKEN so a stolen workflow run can't reach the repo at all +# — least privilege per CodeQL `actions/missing-workflow-permissions`. +permissions: {} + jobs: cleanup: runs-on: ubuntu-latest