पाठ 18 / 25
Least-Privilege Tokens and Branch Protection
The bot proposes; humans and CI decide.
Push to branches, never to main
Give the fix bot a token that can create branches and pull requests, but cannot push to protected branches, approve its own pull requests, change repository settings or read unrelated repositories. Protect the main branch: required status checks, required human approval, no force pushes. Scope tokens per repository, make them short-lived where possible, and log every action the bot takes.
Bot permissions
Allow the minimum.
action bot allowed?
read repository contents yes (only target repos)
create branch autofix/* yes
open / update pull request yes
push to main no (branch protection)
approve or merge its own PR no
edit workflows / settings / secrets no
read organisation secrets noUse a dedicated bot identity
A separate account or app makes bot actions easy to audit and to revoke.
त्वरित जाँच: Which permission should an auto-fix bot NOT have?
- Merging its own pull requests into main
- Creating a branch
- Opening a pull request
- Reading the target repository
Answer
Merging its own pull requests into main — Humans and CI approve merges.