From 1562cbda8e5df013a9922f6bd29c9db94a4e110b Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 28 Jul 2026 12:13:07 -0400 Subject: [PATCH] ci: scope the three reusable CI workflows to contents:read ci-python-sam, ci-typescript-cdk and ci-dotnet declared no permissions at any level, unlike every other workflow here. A reusable workflow that declares nothing inherits the CALLER's token scopes, and these are called from deploy repos, so a lint/test/synth job could run holding an OIDC-mintable token it has no use for. None of the three references GITHUB_TOKEN, github.token, gh, or any secret, so contents:read is all they need to check out and build. Also pass node-version explicitly in the cdk-deploy and ci-node templates. cicd.md requires callers to pin it so lockfileVersion 3 from local Node 24 / npm 11 cannot drift from the runner, but no template did. Only these two targets accept the input; sam-deploy, dotnet-eb, dependency-review and labeler do not, so they are left alone. Verified against all 22 callers across the org that none grants permissions omitting contents:read, so no repo's CI breaks on the caller-cannot-be-exceeded rule. --- .github/workflows/ci-dotnet.yaml | 3 +++ .github/workflows/ci-python-sam.yaml | 3 +++ .github/workflows/ci-typescript-cdk.yaml | 3 +++ workflow-templates/cdk-deploy.yml | 4 ++++ workflow-templates/ci-node.yml | 4 ++++ 5 files changed, 17 insertions(+) diff --git a/.github/workflows/ci-dotnet.yaml b/.github/workflows/ci-dotnet.yaml index b9c1a00..427a470 100644 --- a/.github/workflows/ci-dotnet.yaml +++ b/.github/workflows/ci-dotnet.yaml @@ -20,6 +20,9 @@ on: type: boolean default: true +permissions: + contents: read + jobs: ci: runs-on: ubuntu-latest diff --git a/.github/workflows/ci-python-sam.yaml b/.github/workflows/ci-python-sam.yaml index 95af16e..03b8df5 100644 --- a/.github/workflows/ci-python-sam.yaml +++ b/.github/workflows/ci-python-sam.yaml @@ -44,6 +44,9 @@ on: type: boolean default: true +permissions: + contents: read + jobs: ci: runs-on: ubuntu-latest diff --git a/.github/workflows/ci-typescript-cdk.yaml b/.github/workflows/ci-typescript-cdk.yaml index 0558f77..c239f2d 100644 --- a/.github/workflows/ci-typescript-cdk.yaml +++ b/.github/workflows/ci-typescript-cdk.yaml @@ -56,6 +56,9 @@ on: type: string default: "template.yaml" +permissions: + contents: read + jobs: ci: runs-on: ubuntu-latest diff --git a/workflow-templates/cdk-deploy.yml b/workflow-templates/cdk-deploy.yml index e39cacd..fb65cd3 100644 --- a/workflow-templates/cdk-deploy.yml +++ b/workflow-templates/cdk-deploy.yml @@ -6,5 +6,9 @@ on: jobs: deploy: uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main + with: + # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the + # reusable workflow's default — passed explicitly to pin against drift. + node-version: "24" secrets: deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} diff --git a/workflow-templates/ci-node.yml b/workflow-templates/ci-node.yml index adca81b..c82818a 100644 --- a/workflow-templates/ci-node.yml +++ b/workflow-templates/ci-node.yml @@ -6,3 +6,7 @@ on: jobs: ci: uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main + with: + # Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the + # reusable workflow's default — passed explicitly to pin against drift. + node-version: "24"