From d69ad182528a7bff23cf76814cc96f2431367c83 Mon Sep 17 00:00:00 2001 From: nishimotz Date: Wed, 17 Jun 2026 18:03:59 +0900 Subject: [PATCH] fix(ci): set explicit workflow permissions for GAE deploy Add `permissions: contents: read` so GITHUB_TOKEN is read-only and CodeQL alert actions/missing-workflow-permissions is resolved. --- .github/workflows/appengine-deploy.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/appengine-deploy.yml b/.github/workflows/appengine-deploy.yml index db40b93..6856bbe 100644 --- a/.github/workflows/appengine-deploy.yml +++ b/.github/workflows/appengine-deploy.yml @@ -4,6 +4,9 @@ on: branches: - master +permissions: + contents: read + jobs: deploy: name: GAE deploy