Summary
Clean up GitHub Actions workflow permissions to comply with OpenSSF Scorecard Token-Permissions requirements.
Changes Required
High Priority
Medium Priority
Low Priority
Success Criteria
- All workflows pass CI validation
- Write permissions scoped to job-level only
- Improved OpenSSF Scorecard Token-Permissions check
Summary
Clean up GitHub Actions workflow permissions to comply with OpenSSF Scorecard Token-Permissions requirements.
Changes Required
High Priority
pull-requests: writefromsecurity-scan.ymlMedium Priority
id-token: writetopublishjob only inextension-publish.ymlid-token: writetopublishjob only inextension-publish-prerelease.ymlLow Priority
extension-package.ymlSuccess Criteria