Skip to content

ci(gh permissions): restrict gh token permissions#3815

Open
dsm23 wants to merge 1 commit intoradix-ui:mainfrom
dsm23:ci/restrict-token-permissions
Open

ci(gh permissions): restrict gh token permissions#3815
dsm23 wants to merge 1 commit intoradix-ui:mainfrom
dsm23:ci/restrict-token-permissions

Conversation

@dsm23
Copy link

@dsm23 dsm23 commented Feb 18, 2026

Description

  • Your ossf scorecard score is a little low
  • Try to increase token score by restricting GitHub permissions
  • radix-ui scorecard

I don't think the gh token permissions will affect npmjs registry publishing

* Your ossf scorecard score is a little low
* Try to increase token score by restricting GitHub permissions
* https://scorecard.dev/viewer/?uri=github.com/radix-ui/primitives
@changeset-bot
Copy link

changeset-bot bot commented Feb 18, 2026

⚠️ No Changeset found

Latest commit: 57e9734

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant