Skip to content

[Feature]: Follow the principle of least privilege in workflowsΒ #898

Description

@MacOS

🧠 D: DOCUMENT β€” Problem & Opportunity

What is the problem, limitation, or opportunity? Why does this matter for SKaiNET?

Explain the context in clear terms:

  • What functionality is missing or insufficient?
  • Why is this important now?
  • Who benefits (users, developers, researchers)?
  • What is the high-level goal of this proposal?

Currently, not all workflows follow the principle of least privilege. Which is a security risk.

Summary (1–2 sentences):

Provide a concise overview of what this issue aims to address.

This issue addresee the security problem by only granting privileges that are necessary.


πŸ” A: ASSESS β€” Feasibility & Impact

Provide an evaluation of the proposal. Address the following:

βœ”οΈ Feasibility

  • Is the feature straightforward to implement?
  • Are there architectural constraints?

The changes are straightforward to implement, and has no constraints.

βœ”οΈ Expected Impact

  • How does this improve SKaiNET?
  • Does it unlock new capabilities?

It increases the security of the project.

βœ”οΈ Risks / Constraints

  • Technical challenges?
  • Numerical stability concerns?
  • API consistency?

There are non.

βœ”οΈ Dependencies

  • Does this rely on an existing SKaiNET module?
  • Does it require third-party libraries or standards?

No, it does not.


πŸ“š R: RESEARCH β€” What Must Be Understood First?

Document research tasks or open questions that must be answered before implementation:

Research Tasks

  • Review existing frameworks (PyTorch, JAX, TensorFlow, etc.)
  • Identify relevant algorithms or formulas
  • Compare design patterns for modularity
  • Investigate numerically stable or optimized variants
  • Check for relevant academic papers or benchmarks

There are none.

Open Questions

List unknowns that contributors should discuss or resolve.

There are no unknowns.


πŸ› οΈ C: CODE β€” Implementation Plan

Break down actionable steps required to deliver this feature:

Development Tasks

  • build.yml
  • engine-benchmarks.yml
  • java-tests.yml
  • native-cpu-multiarch.yml
  • publish.yml
  • schema-validation.yml
  • verify-poms.yml

Acceptance Criteria

  • build.yml runs succesfully
  • engine-benchmarks.yml runs succesfully
  • java-tests.yml runs succesfully
  • native-cpu-multiarch.yml runs succesfully
  • publish.yml runs succesfully
  • schema-validation.yml runs succesfully
  • verify-poms.yml runs succesfully

πŸ’¬ Additional Notes

Add diagrams, pseudo-code, references, or implementation notes that may help future contributors.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestgithub_actionsPull requests that update GitHub Actions code

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions