Skip to content

Commit 8ce8969

Browse files
Potential fix for code scanning alert no. 3: Workflow does not contain permissions
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
1 parent 16eaf31 commit 8ce8969

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

.github/workflows/npm-publish.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@ on:
1010
jobs:
1111
build:
1212
runs-on: ubuntu-latest
13+
permissions:
14+
contents: read
1315
steps:
1416
- uses: actions/checkout@v3
1517
- uses: actions/setup-node@v3
@@ -21,6 +23,8 @@ jobs:
2123
publish-npm:
2224
needs: build
2325
runs-on: ubuntu-latest
26+
permissions:
27+
contents: write
2428
steps:
2529
- uses: actions/checkout@v3
2630
- uses: actions/setup-node@v3

0 commit comments

Comments
 (0)