Skip to content

ci: add read-only workflow permissions#27

Merged
Riverbraid merged 1 commit into
mainfrom
phase-4/read-only-workflow-permissions
Jun 3, 2026
Merged

ci: add read-only workflow permissions#27
Riverbraid merged 1 commit into
mainfrom
phase-4/read-only-workflow-permissions

Conversation

@Riverbraid

Copy link
Copy Markdown
Owner

What changed

Adds explicit read-only workflow permissions to the Safety Gold verification workflow.

permissions:
  contents: read

Why

Phase 4 audit remediation identified read-only verification workflows as safer when permissions are explicitly declared.

Scope

Workflow hardening only.
No verifier logic changes.
No registry changes.
No release or tag changes.
No secret changes.
No security-setting claims.

Boundary

This PR does not claim Riverbraid-Safety-Gold is secure, hardened, externally audited, production ready, or defect free.

Status after merge would be PATCHED_UNVERIFIED until workflow evidence is checked.

@Riverbraid Riverbraid merged commit 14ac49f into main Jun 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant