fix(ci): least-privilege permissions + fork-safe concurrency keys

- evals.yml / evals-periodic.yml evals jobs: explicit contents:read +
  packages:read (container-image pull) and persist-credentials:false —
  the jobs that execute PR-authored code with three provider API keys
  ran on the repo-default token grant with the token written into
  .git/config
- permissions blocks for the 4 workflows that had none (skill-docs,
  make-pdf-gate, windows-free-tests, windows-setup-e2e)
- fork-safe concurrency keys: actionlint, skill-docs, make-pdf-gate,
  windows-setup-e2e switch from head_ref to PR-number keying — a bare
  branch name carries no fork prefix, so same-name branches from two
  forks shared one group and cancelled each other's runs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-08-29 04:39:36 +00:00
co-authored by Claude Fable 5
parent 9fbd0700ff
commit e2904be7a4
7 changed files with 46 additions and 7 deletions
+6
View File
@@ -68,6 +68,11 @@ jobs:
evals:
runs-on: ubicloud-standard-8
needs: build-image
# Least privilege (mirrors evals.yml): read-only contents, packages:read
# for the container-image pull.
permissions:
contents: read
packages: read
container:
image: ${{ needs.build-image.outputs.image-tag }}
credentials:
@@ -110,6 +115,7 @@ jobs:
- uses: actions/checkout@v7
with:
fetch-depth: 0
persist-credentials: false
- name: Fix bun temp
run: |