diff options
| author | Yuriy Andamasov <yuriy@vyos.io> | 2026-05-11 01:20:33 +0300 |
|---|---|---|
| committer | Yuriy Andamasov <yuriy@vyos.io> | 2026-05-11 01:20:33 +0300 |
| commit | f288dff64ec236ab564805f4631b7f5c21548b96 (patch) | |
| tree | 2690bd97ee8a45d28c9ccc38a7966256c45ad3f9 /docs/configuration/service/md-https.md | |
| parent | e550631721e90f6d49c94d93a0f9d62cf29334c6 (diff) | |
| download | vyos-documentation-f288dff64ec236ab564805f4631b7f5c21548b96.tar.gz vyos-documentation-f288dff64ec236ab564805f4631b7f5c21548b96.zip | |
ci(ai-validation): scope GitHub App token to permission-contents: read
The token is used only for read-only repo operations (sparse-checkout
of reviewer branches.json, full checkout of vyos-1x, download of the
reference-DB release asset). Without an explicit permission-* input
the token inherits all installation permissions. Scope it down so a
compromise cannot mutate either repo.
Surfaced by CodeRabbit on #1960; applied to all three branch copies
(rolling via #1969 follow-up + circinus #1959 + sagitta #1960) so the
workflow stays in sync across the version-train branches.
🤖 Generated by [robots](https://vyos.io)
Diffstat (limited to 'docs/configuration/service/md-https.md')
0 files changed, 0 insertions, 0 deletions
