Skip to content
Novus Examples
yml568 B

GitHub Actions Over-Permissive Token (Policy Target)

A schema-valid workflow that should still be rejected on review: permissions: write-all at the workflow level plus three unused write scopes on the job. Nothing here is an exploit; it is the least-privilege finding a policy engine is supposed to raise.

Preview — first 21 linesyml
# POLICY-ENGINE TARGET. This workflow parses cleanly and is schema-valid; what it fails is
# least-privilege review. `permissions: write-all` grants every scope to GITHUB_TOKEN, and the
# job-level block re-grants writes the job never uses. A policy engine should flag both.
name: Over-permissive token

on:
  pull_request:

permissions: write-all

jobs:
  label:
    runs-on: ubuntu-latest
    permissions:
      contents: write
      packages: write
      id-token: write
    steps:
      - uses: actions/checkout@v4
      - run: echo "this job only reads contents"

Specifications

System
GitHub Actions
Variant
policy-engine target
Workflow Permissions
write-all
Job Permissions
3
Schema Valid
true

Testing contract

Expected to pass
Scenario
Run a least-privilege policy check over a workflow that parses and validates cleanly
Expected result
The schema check passes while the policy engine raises at least two findings: write-all at workflow level and unused write scopes on the job

What is a .yml file?

YML is an alternate file extension for YAML, a human-readable data-serialization format based on indentation, key-value mappings, and lists. The content and parsing rules are identical to .yaml; only the extension differs. It is widely used for CI and application configuration files.

How to use this file

Use an example YML file to test that config loaders treat .yml and .yaml identically, and to exercise indentation, comment, and multi-document parsing.

How to use this file for testing

“GitHub Actions Over-Permissive Token (Policy Target)” is a deterministic Novus Examples fixture for Config testing, Schema validation, Config parsing. TOML, INI, YAML, .env, and dotfile configuration samples with nested sections and typed values — for testing config parsers, loaders, and environment tooling.

Documented properties for this file: YML · 568 bytes. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.

Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.

Pipeline and infrastructure fixtures are inert configuration: steps reference fictional images and scripts, and nothing here executes. Run your linter, schema validator, migrator, or policy engine against them, and expect the deprecated-syntax and intentionally invalid variants to be rejected.

Point your config loader at the file and assert it reads the documented sections and typed values, including any deliberately-tricky nesting or comments.

Code examples

import yaml  # pip install pyyaml

with open("permissions-write-all.yml") as f:
    data = yaml.safe_load(f)
print(data)

Generated by generation/pipelines.py. Free for any use, no attribution required — license.