Skip to content

Pin GITHUB_TOKEN to contents: read - #2

Merged
SenjuWoo merged 1 commit into
mainfrom
security/codeql-fixes
Sep 4, 2026
Merged

SenjuWoo merged 1 commit into
mainfrom
security/codeql-fixes

Conversation

@SenjuWoo

@SenjuWoo SenjuWoo commented Sep 4, 2026

Copy link
Copy Markdown
Owner

CodeQL actions/missing-workflow-permissions on .github/workflows/ci.yml.

This workflow only checks out the repo and runs tests. Top-level permissions: contents: read is enough; no job uploads artifacts or publishes pages.

No pyproject.toml or requirements.txt at repo root, so Dependabot stays github-actions-only.

CodeQL actions/missing-workflow-permissions: CI only checks out
and runs tests, so the workflow does not need write.
@SenjuWoo
SenjuWoo merged commit 96388e7 into main Sep 4, 2026
7 checks passed
@SenjuWoo
SenjuWoo deleted the security/codeql-fixes branch September 4, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant