Skip to content

Specify default permissions for vrms-data.yml - #8800

Merged
sushma110396 merged 1 commit into
hackforla:gh-pagesfrom
anthonylo87:specify-YML-default-permissions-8588
Sep 29, 2026
Merged

sushma110396 merged 1 commit into
hackforla:gh-pagesfrom
anthonylo87:specify-YML-default-permissions-8588

Conversation

@anthonylo87

@anthonylo87 anthonylo87 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Fixes #8588

What changes did you make?

  • Added top level default permissions to vrms-data.yml, in order to provide/specify minimum required permissions required by the specified workflow.

Why did you make the changes (we will use this info to test)?

  • To align with GitHub security best practices, we want to specify the minimum required permissions for each workflow via a top-level permissions: block to ensure that workflows only have the access they need by default.

CodeQL Alerts

After the PR has been submitted and the resulting GitHub actions/checks have been completed, developers should check the PR for CodeQL alert annotations.

Check the PR's comments. If present on your PR, the CodeQL alert looks similar as shown

Screenshot 2024-10-28 154514

Please let us know that you have checked for CodeQL alerts. Please do not dismiss alerts.

  • I have checked this PR for CodeQL alerts and none were found.
  • I found CodeQL alert(s), and (select one):
    • I have resolved the CodeQL alert(s) as noted
    • I believe the CodeQL alert(s) is a false positive (Merge Team will evaluate)
    • I have followed the Instructions below, but I am still stuck (Merge Team will evaluate)
Instructions for resolving CodeQL alerts

If CodeQL alert/annotations appear, refer to How to Resolve CodeQL alerts.

In general, CodeQL alerts should be resolved prior to PR reviews and merging

Screenshots of Proposed Changes To The Website (if any, please do not include screenshots of code changes)

  • No visual changes to the website
  • Link to test logs: Test Log

Token permissions verified in test logs:

image

@github-actions

Copy link
Copy Markdown

Want to review this pull request? Take a look at this documentation for a step by step guide!


From your project repository, check out a new branch and test the changes.

git checkout -b anthonylo87-specify-YML-default-permissions-8588 gh-pages
git pull https://github.com/anthonylo87/website.git specify-YML-default-permissions-8588

@github-actions github-actions Bot added role: back end/devOps Tasks for back-end developers Complexity: Medium Feature: Refactor GHA Refactoring GitHub actions to fit latest architectural norms size: 5pt Can be done in 19-30 hours labels Sep 24, 2026
@ldaws003

Copy link
Copy Markdown
Member

Review ETA: Friday
Review Availability: Friday 3:00pm to 5:00pm

@ldaws003
ldaws003 self-requested a review September 25, 2026 15:58

@ldaws003 ldaws003 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @anthonylo87, good job on this. You made the required changes of adding the read permissions to vrms-data.yml. Thanks for adding a link and screenshot for the test logs for the job. Approved.

@egcuriel

Copy link
Copy Markdown
Member

Review ETA: 09/27/2026 EOD
Availability: M-Sun (8 pm - 11 pm)

@egcuriel

This comment was marked as duplicate.

@egcuriel egcuriel left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @anthonylo87 !

I tested the GitHub Actions workflow locally using act:

  • Verified that the workflow executes with permissions: contents: read specified
  • The payload was downloaded, filtered, and saved to _data/external/vrms_data.json
  • The git commit was created with the intended message:
    [anthonylo87-specify-YML-default-permissions-8588 97626ccd] Update meeting data

The vrms_data job executes the steps successfully!

@sushma110396
sushma110396 merged commit 911faf7 into hackforla:gh-pages Sep 29, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Complexity: Medium Feature: Refactor GHA Refactoring GitHub actions to fit latest architectural norms role: back end/devOps Tasks for back-end developers size: 5pt Can be done in 19-30 hours

Projects

Development

Successfully merging this pull request may close these issues.

Specify default permissions for vrms-data.yml

4 participants