fix(security): add workflow permissions and update security SLA - #55
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved review issues were identified.
Review effort: Lite
Findings: None
What changed in this PR
This PR hardens CI permissions, updates GitHub Actions dependencies, and revises the security-report acknowledgment policy.
Changes:
- Adds read-only workflow permissions.
- Updates checkout and Go setup actions.
- Replaces the fixed 48-hour security SLA.
| File | Description |
|---|---|
SECURITY.md |
Updates vulnerability-report acknowledgment expectations. |
.github/workflows/go.yml |
Adds least-privilege permissions and newer action versions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
permissions: contents: readto.github/workflows/go.yml.go.yml(actions/checkout@v4,actions/setup-go@v5).SECURITY.mdwith practical acknowledgment expectation.Risk
Low risk — CI workflow permission hardening and documentation realism.