Skip to content

Commit a2eb986

Browse files
Potential fix for code scanning alert no. 5: Workflow does not contain permissions (#48)
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
1 parent 87b468c commit a2eb986

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

.github/workflows/ci.yaml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,8 @@ jobs:
2828
test:
2929
runs-on: ubuntu-latest
3030
needs: setup
31+
permissions:
32+
contents: read
3133
steps:
3234
- name: Checkout code
3335
uses: actions/checkout@v3
@@ -54,6 +56,8 @@ jobs:
5456
vulncheck:
5557
runs-on: ubuntu-latest
5658
needs: test
59+
permissions:
60+
contents: read
5761
steps:
5862
- name: Checkout code
5963
uses: actions/checkout@v3
@@ -71,6 +75,9 @@ jobs:
7175
runs-on: ubuntu-latest
7276
needs: test # Ensure changelog runs only if tests pass
7377
if: github.event_name == 'pull_request' # Run only for pull requests
78+
permissions:
79+
contents: read
80+
pull-requests: write
7481
steps:
7582
- name: Checkout code
7683
uses: actions/checkout@v3
@@ -83,6 +90,8 @@ jobs:
8390
report-card:
8491
runs-on: ubuntu-latest
8592
needs: test # Ensure report card runs only if tests pass
93+
permissions:
94+
contents: read
8695
steps:
8796
- name: Checkout code
8897
uses: actions/checkout@v3

0 commit comments

Comments
 (0)