Skip to content

Potential fix for code scanning alert no. 1: Workflow does not contain permissions - #8

Draft
Pradyothsp wants to merge 1 commit into
mainfrom
alert-autofix-1
Draft

Pradyothsp wants to merge 1 commit into
mainfrom
alert-autofix-1

Conversation

@Pradyothsp

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/Pradyothsp/govec-python/security/code-scanning/1

Add an explicit top-level permissions block in .github/workflows/release.yml so every job (including the reusable test job) has restricted default token access unless overridden per-job.
Best fix here: set workflow-level default to read-only for repository contents:

  • Add, near the top of the workflow (after on: block is a clean spot),:
    • permissions:
    • contents: read

This preserves existing behavior:

  • publish keeps its job-level id-token: write.
  • release keeps its job-level contents: write.
  • test and build get explicit least-privilege defaults instead of implicit inherited defaults.

No imports, methods, or dependencies are needed.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant