-
Notifications
You must be signed in to change notification settings - Fork 2
🌿 Fern Regeneration -- August 29, 2025 #12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
03c374f
to
0354fac
Compare
runs-on: ubuntu-latest | ||
steps: | ||
- uses: actions/checkout@v4 | ||
|
||
- name: Install Rye | ||
- name: Checkout repo | ||
uses: actions/checkout@v4 | ||
- name: Set up python | ||
uses: actions/setup-python@v4 | ||
with: | ||
python-version: 3.8 | ||
- name: Bootstrap poetry | ||
run: | | ||
curl -sSf https://rye.astral.sh/get | bash | ||
echo "$HOME/.rye/shims" >> $GITHUB_PATH | ||
env: | ||
RYE_VERSION: '0.44.0' | ||
RYE_INSTALL_OPTION: '--yes' | ||
|
||
- name: Bootstrap | ||
run: ./scripts/bootstrap | ||
curl -sSL https://install.python-poetry.org | python - -y --version 1.5.1 | ||
- name: Install dependencies | ||
run: poetry install | ||
|
||
- name: Run tests | ||
run: ./scripts/test | ||
- name: Test | ||
run: poetry run pytest -rP . |
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 22 days ago
To fix the problem, the workflow requires a permissions
block that restricts the permissions of the GITHUB_TOKEN
used by the job(s). The preferred way is to add this block at the workflow root, which applies it to all jobs in the workflow unless overridden. As both compile
and test
jobs only read repository contents, you should use permissions: contents: read
at the top level (just below the workflow name and/or events trigger section and above jobs:
). No additional imports or definitions are required—just a single YAML mapping in the appropriate place.
-
Copy modified lines R4-R5
@@ -1,6 +1,8 @@ | ||
name: ci | ||
|
||
on: [push] | ||
permissions: | ||
contents: read | ||
jobs: | ||
compile: | ||
runs-on: ubuntu-latest |
This PR regenerates code to match the latest API Definition.