Skip to content

Conversation

@vvalderrv
Copy link
Contributor

This is a test workflow to validate the sonar token. PR will be closed
after the test is complete

This patch is for a throw away workflow to check the sonar token
The PR will be closed after the check is done

Signed-off-by: Vanessa Valderrama <[email protected]>
@@ -0,0 +1,32 @@
name: Sonar Token Check

Check failure

Code scanning / Scorecard

Token-Permissions

score is 0: no topLevel permission defined Remediation tip: Visit [https://app.stepsecurity.io/secureworkflow](https://app.stepsecurity.io/secureworkflow//sonar-token-check.yml/?enable=permissions). Tick the 'Restrict permissions for GITHUB_TOKEN' Untick other options NOTE: If you want to resolve multiple issues at once, you can visit [https://app.stepsecurity.io/securerepo](https://app.stepsecurity.io/securerepo) instead. Click Remediation section below for further remediation help
This is a test workflow to validate the sonar token. PR will be closed
after the test is complete

Signed-off-by: Vanessa Valderrama <[email protected]>
@vvalderrv vvalderrv closed this Sep 26, 2025
@lgritz lgritz added the build / testing / port / CI Affecting the build system, tests, platform support, porting, or continuous integration. label Oct 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build / testing / port / CI Affecting the build system, tests, platform support, porting, or continuous integration.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants