summaryrefslogtreecommitdiff
path: root/docs/configuration/service/md-https.md
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-11 01:20:33 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-11 01:20:33 +0300
commitf288dff64ec236ab564805f4631b7f5c21548b96 (patch)
tree2690bd97ee8a45d28c9ccc38a7966256c45ad3f9 /docs/configuration/service/md-https.md
parente550631721e90f6d49c94d93a0f9d62cf29334c6 (diff)
downloadvyos-documentation-f288dff64ec236ab564805f4631b7f5c21548b96.tar.gz
vyos-documentation-f288dff64ec236ab564805f4631b7f5c21548b96.zip
ci(ai-validation): scope GitHub App token to permission-contents: read
The token is used only for read-only repo operations (sparse-checkout of reviewer branches.json, full checkout of vyos-1x, download of the reference-DB release asset). Without an explicit permission-* input the token inherits all installation permissions. Scope it down so a compromise cannot mutate either repo. Surfaced by CodeRabbit on #1960; applied to all three branch copies (rolling via #1969 follow-up + circinus #1959 + sagitta #1960) so the workflow stays in sync across the version-train branches. 🤖 Generated by [robots](https://vyos.io)
Diffstat (limited to 'docs/configuration/service/md-https.md')
0 files changed, 0 insertions, 0 deletions