Skip to content

Conversation

@anomiex
Copy link
Contributor

@anomiex anomiex commented Nov 25, 2025

Closes MONOREP-263

Proposed changes:

Mostly through static analysis. A few made use of docs for other actions.

See inline comments for the main notes on what things need. Other notes:

  • .github/actions/turnstile - It has docs, may as well mention it (theoretically) needing actions: read.
  • coverage-check: Already had some set, but it turns out it doesn't need most of them anymore. It uses the app token for almost everything instead of the default Actions token.
  • update-phan-stubs: This one also had permissions set that it doesn't need. It even uses a matticbot token for the checkout, so none needed at all.

Also the following already had permissions that seem correct:

  • build-docker
  • build-docker-monorepo
  • post-build

Leaving build, e2e-tests, tests, and wpcloud for a later PR.

Other information:

  • Have you written new tests for your changes, if applicable?
  • Have you checked the E2E test CI results, and verified that your changes do not break them?
  • Have you tested your changes on WordPress.com, if applicable (if so, you'll see a generated comment below with a script to run)?

Jetpack product discussion

Followup to #46067

Does this pull request change what data or activity we track or use?

No

Testing instructions:

Mostly through static analysis. A few made use of docs for other
actions.

See inline comments for the main notes on what things need.
Other notes:

* `.github/actions/turnstile` - It has docs, may as well mention it
  (theoretically) needing `actions: read`.
* coverage-check: Already had some set, but it turns out it doesn't need
  most of them anymore. It uses the app token for almost everything
  instead of the default Actions token.
* update-phan-stubs: This one also had permissions set that it doesn't
  need. It even uses a matticbot token for the checkout, so none needed
  at all.

Also the following already had permissions that seem correct:

* build-docker
* build-docker-monorepo
* post-build

Leaving build, e2e-tests, tests, and wpcloud for a later PR.
@anomiex anomiex requested a review from a team November 25, 2025 21:29
@anomiex anomiex self-assigned this Nov 25, 2025
@github-actions github-actions bot added Actions GitHub actions used to automate some of the work around releases and repository management Docs labels Nov 25, 2025
@github-actions
Copy link
Contributor

Thank you for your PR!

When contributing to Jetpack, we have a few suggestions that can help us test and review your patch:

  • ✅ Include a description of your PR changes.
  • ✅ Add a "[Status]" label (In Progress, Needs Review, ...).
  • ✅ Add a "[Type]" label (Bug, Enhancement, Janitorial, Task).
  • ✅ Add testing instructions.
  • ✅ Specify whether this PR includes any changes to data or privacy.
  • ✅ Add changelog entries to affected projects

This comment will be updated as you work on your PR and make changes. If you think that some of those checks are not needed for your PR, please explain why you think so. Thanks for cooperation 🤖


Follow this PR Review Process:

  1. Ensure all required checks appearing at the bottom of this PR are passing.
  2. Make sure to test your changes on all platforms that it applies to. You're responsible for the quality of the code you ship.
  3. You can use GitHub's Reviewers functionality to request a review.
  4. When it's reviewed and merged, you will be pinged in Slack to deploy the changes to WordPress.com simple once the build is done.

If you have questions about anything, reach out in #jetpack-developers for guidance!

Copy link
Contributor

@tbradsha tbradsha left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing stands out as a problem here.

@anomiex
Copy link
Contributor Author

anomiex commented Nov 26, 2025

🤞

@anomiex anomiex merged commit 2f2c901 into trunk Nov 26, 2025
84 checks passed
@anomiex anomiex deleted the update/set-permissions-for-various-smaller-workflows branch November 26, 2025 14:49
@github-actions github-actions bot removed the [Status] Needs Review This PR is ready for review. label Nov 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Actions GitHub actions used to automate some of the work around releases and repository management Docs [Pri] Normal [Type] Janitorial

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants