GitHub Actions Over-Permissive Token (Policy Target)
A schema-valid workflow that should still be rejected on review: permissions: write-all at the workflow level plus three unused write scopes on the job. Nothing here is an exploit; it is the least-privilege finding a policy engine is supposed to raise.
# POLICY-ENGINE TARGET. This workflow parses cleanly and is schema-valid; what it fails is
# least-privilege review. `permissions: write-all` grants every scope to GITHUB_TOKEN, and the
# job-level block re-grants writes the job never uses. A policy engine should flag both.
name: Over-permissive token
on:
pull_request:
permissions: write-all
jobs:
label:
runs-on: ubuntu-latest
permissions:
contents: write
packages: write
id-token: write
steps:
- uses: actions/checkout@v4
- run: echo "this job only reads contents"
Specifications
- System
- GitHub Actions
- Variant
- policy-engine target
- Workflow Permissions
- write-all
- Job Permissions
- 3
- Schema Valid
- true
Testing contract
Expected to pass- Scenario
- Run a least-privilege policy check over a workflow that parses and validates cleanly
- Expected result
- The schema check passes while the policy engine raises at least two findings: write-all at workflow level and unused write scopes on the job
What is a .yml file?
YML is an alternate file extension for YAML, a human-readable data-serialization format based on indentation, key-value mappings, and lists. The content and parsing rules are identical to .yaml; only the extension differs. It is widely used for CI and application configuration files.
How to use this file
Use an example YML file to test that config loaders treat .yml and .yaml identically, and to exercise indentation, comment, and multi-document parsing.
How to use this file for testing
“GitHub Actions Over-Permissive Token (Policy Target)” is a deterministic Novus Examples fixture for Config testing, Schema validation, Config parsing. TOML, INI, YAML, .env, and dotfile configuration samples with nested sections and typed values — for testing config parsers, loaders, and environment tooling.
Documented properties for this file: YML · 568 bytes. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
Pipeline and infrastructure fixtures are inert configuration: steps reference fictional images and scripts, and nothing here executes. Run your linter, schema validator, migrator, or policy engine against them, and expect the deprecated-syntax and intentionally invalid variants to be rejected.
Point your config loader at the file and assert it reads the documented sections and typed values, including any deliberately-tricky nesting or comments.
Code examples
import yaml # pip install pyyaml
with open("permissions-write-all.yml") as f:
data = yaml.safe_load(f)
print(data)Related files
- yamlAttestation Verification Policy (YAML)The policy an admission controller evaluates before an artifact is allowed through: required predicate types, an allowed-builder list, a minimum SLSA level, a transparency-log requirement and one dated exception. Every package, version, hash and licence is fictional — the tree describes nothing real.

- yamlVulnerability Suppression Policy (YAML)A suppression policy that gives every waiver an owner, a reason and an expiry date — the fields that stop a suppression file becoming a permanent blindfold. All four entries are SAMPLE. Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists.

- ymlGitHub Actions Composite Action DefinitionAn action.yml-shaped composite action definition with typed inputs, a declared output bound to a step output, and a branding block. Distinct from a workflow file, and a common blind spot in workflow linters that only understand .github/workflows.

- ymlGitHub Actions Concurrency and EnvironmentA deployment workflow exercising the blocks that governance tools care about: a concurrency group with cancel-in-progress, paths-ignore filters, a named environment with a URL, and a job timeout. All hosts are example.invalid.

- ymlGitHub Actions Deprecated Workflow CommandsA deprecated-syntax workflow: ::set-output, ::set-env and ::add-path markers, a retired runner label, and v2 action pins. Every construct here was removed from the runner, so an upgrade migrator can be scored on whether it rewrites all of them.

- ymlGitHub Actions Expression and Function CoverageAn expression-dense workflow: fromJSON-generated matrix axes, hashFiles cache keys, format and join calls, a folded multi-line if condition, and the && / || coalescing idiom that stands in for a ternary. For testing template resolvers before any schema check.

Generated by generation/pipelines.py. Free for any use, no attribution required — license.