Skip to content

Potential fix for code scanning alert no. 2: Workflow does not contain permissions - #1

Merged
doug445 merged 1 commit into
mainfrom
alert-autofix-2
Aug 21, 2026
Merged

doug445 merged 1 commit into
mainfrom
alert-autofix-2

Conversation

@doug445

@doug445 doug445 commented Aug 21, 2026

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/doug445/AsahiLocker/security/code-scanning/2

Add an explicit permissions block at the workflow root in .github/workflows/lint.yml, immediately after the on: triggers and before jobs:. Since both jobs only need to read repository contents (for checkout and file-based lint/test commands), the least-privilege setting is:

  • contents: read

This is the best single fix because it applies to all jobs uniformly without changing job behavior, and avoids duplicating permissions per job. No imports, methods, or dependencies are needed—just YAML configuration.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@doug445
doug445 marked this pull request as ready for review August 21, 2026 22:48
@doug445
doug445 merged commit 039ceb0 into main Aug 21, 2026
9 checks passed
doug445 added a commit that referenced this pull request Aug 31, 2026
Potential fix for code scanning alert no. 2: Workflow does not contain permissions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant