Skip to content

ci: harden SCIP workflow permissions - #163

Open
grtninja wants to merge 1 commit into
sourcegraph:masterfrom
grtninja:codex/ci-harden-scip-workflow
Open

ci: harden SCIP workflow permissions#163
grtninja wants to merge 1 commit into
sourcegraph:masterfrom
grtninja:codex/ci-harden-scip-workflow

Conversation

@grtninja

Copy link
Copy Markdown

Summary

  • pin actions/checkout in .github/workflows/scip.yml to an immutable commit SHA
  • add explicit minimal permissions for the workflow token

Why

This keeps the existing SCIP upload flow intact while making the workflow a little
safer and more explicit:

  • the checkout action no longer floats on a tag
  • the workflow token is limited to contents: read
  • the change stays one-file and behavior-preserving

Related public lane: this follows the same workflow-hardening pattern as
NousResearch/hermes-agent#7646 and Aider-AI/aider#5021.

Validation

  • YAML parse of .github/workflows/scip.yml
  • git diff --check

No Go source files or runtime code paths were changed in this patch.

Pin actions/checkout in the SCIP workflow to an immutable commit SHA and trim the workflow token to contents: read. This keeps the existing upload behavior while reducing tag drift and default token scope without changing the workflow surface.

Signed-off-by: grtninja <grtninja@hotmail.com>

grtninja commented Aug 8, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-08T22:00:38Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; changed files=1
  • Checks/workflows observed at this head: no status/workflow result exposed by the current connector surface
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer/review follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer nudge; re-read this exact head/diff before any review reply.

This is a public-safe coordination receipt only. No push, merge, publication, credential, runtime, model, GPU, auth, or protected-reasoning mutation was performed or authorized by this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T04:01:16Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; changed files=1
  • Checks/workflows observed at this head: no status/workflow result exposed by the current connector surface
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer/review follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer nudge; re-read this exact head/diff before any review reply.

This is a public-safe coordination receipt only. No push, merge, publication, credential, runtime, model, GPU, auth, or protected-reasoning mutation was performed or authorized by this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T10:00:48Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; changed files=1
  • Checks/workflows observed at this head: none reported
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer/review follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T16:01:56Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; observed merge-state=see live inventory; changed files=1
  • Checks/workflows at this head: none reported
  • Review state: 0 reviews (latest none) / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

grtninja commented Aug 9, 2026

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-09T22:00:57Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; observed merge-state=see authoritative REST inventory; changed files=1
  • Checks/workflows at this head: none reported
  • Review state: 0 reviews (latest none) / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-10T04:00:32Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN / ready / mergeable=true; observed merge-state=see authoritative REST inventory; changed files=1
  • Checks/workflows at this head: none reported
  • Review state: 0 reviews / 0 review threads / 0 current unresolved
  • Current unresolved paths: none
  • Contributor guidance recheck: CONTRIBUTING.md
  • Exact-surface overlap: none detected among this open-PR union
  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.
  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.
  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-10T10:00:38Z

  • Fresh 10:01Z refresh: authoritative 34-PR union unchanged versus 04:00Z; no head, state, merge-state, review/thread, check, or changed-file deltas.

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions

  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)

  • State: OPEN / ready / mergeable=true; observed merge-state=see authoritative REST inventory; changed files=1

  • Checks/workflows at this head: none reported

  • Review state: 0 reviews / 0 review threads / 0 current unresolved

  • Current unresolved paths: none

  • Contributor guidance recheck: CONTRIBUTING.md

  • Exact-surface overlap: none detected among this open-PR union

  • Owner next bounded action: Owner: re-read the exact current head/diff, run the narrowest relevant validation, and keep maintainer follow-up moving without duplicate bot triggers.

  • Bot/review policy: no duplicate bot trigger and no human maintainer-review nudge; re-read current head/diff before any reply.

  • Coordination boundary: public-safe packet only; no push, merge, publish, protected model/reasoning mutation, or process restart in this pass.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-10 16:01:44Z

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-10 22:01:41Z

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-11 04:00:16Z

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-11 10:01:08Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / base cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN; mergeability clean (REST mergeable=true)
  • Fresh evidence: author/involves union refreshed at 2026-08-11T10:01:08Z; 34/34 PR info, reviews, threads, issue comments, checks, and file lists returned successfully. Direct REST refresh is 34/34; structural comparison vs 04:00Z has no head/base/state/draft/changed-file movement; three MemPalace mergeability fields are transient unknown and remain recheck-only. The 28 REST comment-count increments are the expected 04:00 coordination packets; no substantive post-04 issue-comment delta was observed.
  • Reviews/threads: 0 review submissions; 0 inline review threads; 0 currently unresolved.
  • Checks: none returned.
  • Changed surface: 1 file(s). Contributor guidance, exact-surface overlap, and current-head review state were rechecked.
  • Owner next action: Owner: re-read the current head and diff, address any current review findings, and run the narrowest relevant validation.
  • Priority blockers: none observed on the current review-thread snapshot.
  • Coordination guard: no duplicate bot trigger, no human maintainer nudge, no push/merge/publish, and no protected model/reasoning mutation. G07 Main Arbiter remains unchanged; this packet preserves the recipient's current model/reasoning.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-11 16:01:08Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / base cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN; mergeability clean (REST mergeable=true)
  • Fresh evidence: author/involves union refreshed at 2026-08-11T16:01:08Z; current open union is 32 PRs across 22 repositories (30 authored plus 2 owned Dependabot). 32/32 PR-info, reviews, threads, issue comments, checks, and file lists returned successfully. Direct REST refreshed all 34 prior records: 32 remain open; docs: remove GitHub Discussions reference from contributing guide MemPalace/mempalace#555 and #597 are now CLOSED/MERGED and are removed from this open-pass scope. #2070 is now REST dirty/mergeable=false (not the prior transient unknown). The 26 one-comment count increments are expected from the 10:00 packets that remain open; no substantive post-10:00 issue-comment delta was observed.
  • Reviews/threads: 0 review submissions; 0 inline review threads; 0 currently unresolved.
  • Checks: none returned.
  • Changed surface: 1 file(s). Contributor guidance, exact-surface overlap, base freshness, and current-head review state were rechecked.
  • Owner next action: Owner: re-read current head/diff, address current review findings, and run the narrowest relevant validation.
  • Priority blockers: none observed on current review-thread snapshot.
  • Coordination guard: no duplicate bot trigger, no human maintainer nudge, no push/merge/publish, and no protected model/reasoning mutation. G07 Main Arbiter remains unchanged; this packet preserves the recipient's current model/reasoning.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-11 22:00:42Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / base cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN; mergeability clean (REST mergeable=true)
  • Fresh evidence: author/involves union refreshed at 2026-08-11T22:00:42Z; current open union remains 32 PRs across 22 repositories (30 authored plus 2 owned Dependabot). 32/32 PR-info, reviews, threads, issue comments, checks, and file lists returned successfully. Direct REST rechecked all 34 historical records: 32 remain open, with no current head/base/state/draft/merge-state/mergeability/changed-file movement versus 16:00Z. The 26 one-comment count increments are expected from the 16:00 packets; no substantive post-16:00 issue-comment delta was observed.
  • Reviews/threads: 0 review submissions; 0 inline review threads; 0 currently unresolved.
  • Checks: none returned.
  • Changed surface: 1 file(s). Contributor guidance, exact-surface overlap, base freshness, and current-head review state were rechecked.
  • Owner next action: Owner: re-read current head/diff, address current review findings, and run the narrowest relevant validation.
  • Priority blockers: none observed on current review-thread snapshot.
  • Coordination guard: no duplicate bot trigger, no human maintainer nudge, no push/merge/publish, and no protected model/reasoning mutation. G07 Main Arbiter remains unchanged; this packet preserves the recipient's current model/reasoning.

Copy link
Copy Markdown
Author

Current-head coordination packet — 2026-08-12 04:01:48Z

  • PR: ci: harden SCIP workflow permissions #163 — ci: harden SCIP workflow permissions
  • Exact head/base: 935ef24f82a6d0365020e22f42b8a8ec8b44cf50 / base cdc8b7899beb72d7ffcf9b2a0e8b591add164150 (master)
  • State: OPEN; mergeability clean (REST mergeable=true)
  • Fresh evidence: author/involves union refreshed at 2026-08-12T04:01:48Z; current open union remains 32 PRs across 22 repositories (30 authored plus 2 owned Dependabot). 32/32 PR-info, reviews, threads, issue comments, checks, and file lists returned successfully. Direct REST rechecked all 34 historical records: 32 remain open, with no current head/base/state/draft/merge-state/mergeability/changed-file movement versus 22:00Z. The 26 one-comment count increments are expected from the 22:00 packets; no substantive post-22:00 issue-comment delta was observed.
  • Reviews/threads: 0 review submissions; 0 inline review threads; 0 currently unresolved.
  • Checks: none returned.
  • Changed surface: 1 file(s). Contributor guidance, exact-surface overlap, base freshness, and current-head review state were rechecked.
  • Owner next action: Owner: re-read current head/diff, address current review findings, and run the narrowest relevant validation.
  • Priority blockers: none observed on current review-thread snapshot.
  • Coordination guard: no duplicate bot trigger, no human maintainer nudge, no push/merge/publish, and no protected model/reasoning mutation. G07 Main Arbiter remains unchanged; this packet preserves the recipient's current model/reasoning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant