Skip to content

Restrict ret-turkey workflow to minimum required permissions - #754

Merged
DougReeder merged 1 commit into
masterfrom
secure-turkeyGitops-caller-workflow
Jul 7, 2026
Merged

DougReeder merged 1 commit into
masterfrom
secure-turkeyGitops-caller-workflow

Conversation

@Exairnous

Copy link
Copy Markdown
Member

What?

Sets the permissions of the ret-turkey workflow to none.

Why?

To minimize the chance of the workflow being hacked and in preparation to globally restrict permissions for all Hubs Foundation workflows.

Examples

N/A

How to test

  1. See Increase turkeyGitops workflow security and tighten permissions hubs-ops#215

Documentation of functionality

This doesn't change the functionality of the workflow, so no documentation update is needed.

Known limitations

None.

Alternative implementations considered

None.

Open questions

None.

Additional details or related context

The permissions setting was advised by GitHubSecurityLab/actions-permissions/monitor@bf82d13b9b10051d224345ab9184f5ede0a94289 #v1 Beta 9

Companion to: Hubs-Foundation/hubs-ops#215

Part of Hubs-Foundation/.github#13

What: sets the permissions of the ret-turkey workflow to none.

Why: to minimize the chance of the workflow being hacked and in preparation to globally restrict permissions for all Hubs Foundation workflows.

Note: the permissions setting was advised by `GitHubSecurityLab/actions-permissions/monitor@bf82d13b9b10051d224345ab9184f5ede0a94289 #v1 Beta 9`
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

Thank you for the pull request.

ROADMAP STATUS: This pull request isn't currently on any roadmap. Updates will be conveyed here as its place on/off a roadmap changes.

You can view the roadmaps here: Roadmaps Google Drive folder.

For more information on how the roadmaps work, see our roadmaps policy on GitHub.

@Exairnous Exairnous added the Roadmap: Programming Indicates that this issue/pull request is on the Programming Team roadmap label Jul 6, 2026

@DougReeder DougReeder left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@DougReeder
DougReeder merged commit 64188ba into master Jul 7, 2026
6 of 25 checks passed
@DougReeder
DougReeder deleted the secure-turkeyGitops-caller-workflow branch July 7, 2026 16:29
Exairnous added a commit that referenced this pull request Jul 12, 2026
What: sets the permissions of the ret-turkey workflow to none.

Why: to minimize the chance of the workflow being hacked and in preparation to globally restrict permissions for all Hubs Foundation workflows.

Note: the permissions setting was advised by `GitHubSecurityLab/actions-permissions/monitor@bf82d13b9b10051d224345ab9184f5ede0a94289 #v1 Beta 9`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Roadmap: Programming Indicates that this issue/pull request is on the Programming Team roadmap

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants