Skip to content

Conversation

@anomiex
Copy link
Contributor

@anomiex anomiex commented Nov 19, 2025

Closes MONOREP-235

Proposed changes:

GitHub's code scanner keeps complaining at us about permissions. Let's try the GitHubSecurityLab/actions-permissions action they mentioned in a blog post a few years ago to see how it does on a few of our workflows at analyzing which permissions are required.

Other information:

  • Have you written new tests for your changes, if applicable?
  • Have you checked the E2E test CI results, and verified that your changes do not break them?
  • Have you tested your changes on WordPress.com, if applicable (if so, you'll see a generated comment below with a script to run)?

Jetpack product discussion

None

Does this pull request change what data or activity we track or use?

No

Testing instructions:

  • CI happy?

GitHub's code scanner keeps complaining at us about permissions. Let's
try the `GitHubSecurityLab/actions-permissions` action they mentioned in
[a blog post a few years ago][1] to see how it does on a few of our
workflows at analyzing which permissions are required.

[1]: https://github.blog/security/new-tool-to-secure-your-github-actions/
@anomiex anomiex requested a review from a team November 19, 2025 19:48
@anomiex anomiex self-assigned this Nov 19, 2025
@anomiex anomiex added [Type] Enhancement Changes to an existing feature — removing, adding, or changing parts of it [Status] In Progress [Pri] Normal labels Nov 19, 2025
@github-actions
Copy link
Contributor

Thank you for your PR!

When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:

  • ✅ Include a description of your PR changes.
  • ✅ Add a "[Status]" label (In Progress, Needs Review, ...).
  • ✅ Add a "[Type]" label (Bug, Enhancement, Janitorial, Task).
  • ✅ Add testing instructions.
  • ✅ Specify whether this PR includes any changes to data or privacy.
  • ✅ Add changelog entries to affected projects

This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖


Follow this PR Review Process:

  1. Ensure all required checks appearing at the bottom of this PR are passing.
  2. Make sure to test your changes on all platforms that it applies to. You're responsible for the quality of the code you ship.
  3. You can use GitHub's Reviewers functionality to request a review.
  4. When it's reviewed and merged, you will be pinged in Slack to deploy the changes to WordPress.com simple once the build is done.

If you have questions about anything, reach out in #jetpack-developers for guidance!

@github-actions github-actions bot added the Actions GitHub actions used to automate some of the work around releases and repository management label Nov 19, 2025
GitHubSecurityLab/actions-permissions/monitor takes a minute to start.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Actions GitHub actions used to automate some of the work around releases and repository management [Pri] Normal [Status] In Progress [Type] Enhancement Changes to an existing feature — removing, adding, or changing parts of it

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants