Skip to content

[Aikido] AI Fix for Overly Broad Permissions in GitHub Actions Workflows is risky - #297

Merged
Kvarkas merged 7 commits into
svelteKitfrom
fix/aikido-security-sast-121315106-bzdu
Sep 22, 2026
Merged

Kvarkas merged 7 commits into
svelteKitfrom
fix/aikido-security-sast-121315106-bzdu

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

This patch mitigates excessive workflow-level permissions by replacing the workflow-level permissions block with an empty block and granting the minimum required scopes per job: contents write for the build job that performs git operations, and pages write plus id-token write for the deploy job that deploys to GitHub Pages.

Aikido used AI to generate this PR.

Low confidence: Aikido has tested similar fixes, which indicate the correct approach but may be incomplete. Further validation is necessary.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The build job retains repository-write access during dependency installation and site compilation.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Scopes GitHub Actions permissions per job for least-privilege Pages deployment.

Changes:

  • Removes workflow-wide permissions.
  • Grants build and deploy jobs separate permissions.
File Description
.github/​workflows/​deploy.yml Moves permissions to job scope.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +19 to +20
permissions:
contents: write

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implemented in 5ba8e46. The workflow now isolates nightly metadata update/commit into a repository_dispatch-only write-scoped job, while build jobs run with read-only repository permissions and separate dispatch/non-dispatch paths.

Co-authored-by: Kvarkas <3611964+Kvarkas@users.noreply.github.com>
Copilot AI and others added 5 commits September 22, 2026 08:46
Co-authored-by: Kvarkas <3611964+Kvarkas@users.noreply.github.com>
Co-authored-by: Kvarkas <3611964+Kvarkas@users.noreply.github.com>
Co-authored-by: Kvarkas <3611964+Kvarkas@users.noreply.github.com>
Co-authored-by: Kvarkas <3611964+Kvarkas@users.noreply.github.com>
Co-authored-by: Kvarkas <3611964+Kvarkas@users.noreply.github.com>
@Kvarkas
Kvarkas merged commit 6b60025 into svelteKit Sep 22, 2026
4 checks passed
@Kvarkas
Kvarkas deleted the fix/aikido-security-sast-121315106-bzdu branch September 22, 2026 10:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants