security(scorecard): Token-Permissions alert on scorecard.yml is 19 days stale (CSA001/CSA003) · Issue #268 · hyperpolymath/echo-types · GitHub
Skip to content

security(scorecard): Token-Permissions alert on scorecard.yml is 19 days stale (CSA001/CSA003) #268

Description

@hyperpolymath

Hypatia code_scanning_alerts CSA001 + CSA003 (both high), surfaced on the #266 scan.

Code scanning (Scorecard): TokenPermissionsID — Token-Permissions — 19 day(s) old [STALE] at .github/workflows/scorecard.yml (threshold: 7 days) — overdue for remediation.

Assessment (verified): genuine, pre-existing (predates the close-out session), independent of any docs change. CSA001 and CSA003 are the same underlying alert (stale + overdue framings). The ledger classifies scorecard.yml under the billing-wall "pattern B" parking, but least-privilege permissions: hardening (the Token-Permissions remediation) is separate from the billing issue and worth doing on its own.

Disposition: owner governance call. Remediation = pin explicit least-privilege permissions: blocks in .github/workflows/scorecard.yml (and confirm the code-scanning alert clears). Not auto-applied — workflow/security changes are deliberate owner actions.

Source: Hypatia neurosymbolic scan on #266.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions