Skip to content

Conversation

@bigcat88
Copy link
Contributor

@bigcat88 bigcat88 commented Aug 4, 2025

This PR should remove the Medium security complaints:

Screenshot from 2025-08-04 19-12-44

In publish_package.yml

permissions:
  contents: read

should be ok, as the next lines are still present for publishing at the job level that has higher priority then global one:

permissions:
      id-token: write  # IMPORTANT: this permission is mandatory for trusted 

@dosubot dosubot bot added the size:M This PR changes 30-99 lines, ignoring generated files. label Aug 4, 2025
@codecov
Copy link

codecov bot commented Aug 4, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.

@@           Coverage Diff           @@
##             main     #305   +/-   ##
=======================================
  Coverage        ?   47.91%           
=======================================
  Files           ?       30           
  Lines           ?     3068           
  Branches        ?        0           
=======================================
  Hits            ?     1470           
  Misses          ?     1598           
  Partials        ?        0           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dosubot dosubot bot added size:S This PR changes 10-29 lines, ignoring generated files. and removed size:M This PR changes 30-99 lines, ignoring generated files. labels Aug 4, 2025
@bigcat88 bigcat88 merged commit 21f719e into main Aug 4, 2025
8 checks passed
@bigcat88 bigcat88 deleted the chore/ci/token-permissions branch August 4, 2025 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S This PR changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants