From 0acbb5cfd88fcd8278f8edfcff4cb82722457cc0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Christian=20Gonz=C3=A1lez=20Di=20Antonio?= Date: Sun, 4 Oct 2026 16:56:25 +0200 Subject: [PATCH] ci: the pull request workflow's token can read the repository and nothing else The workflow had no permissions block, so its GITHUB_TOKEN got the repository's default grants (code scanning alert 2, actions/missing-workflow-permissions). The job checks out, builds, tests and writes a step summary: contents: read is all it needs. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/pr.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index df0d7f1..3d0e3fa 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -8,6 +8,12 @@ on: env: MAKE_STOP_ON_ERRORS: true +# The job checks the code out, builds and tests it, and writes its report to +# the step summary. It needs to read the repository and nothing else; without +# this block the token gets whatever the repository's default grants. +permissions: + contents: read + jobs: build: runs-on: ubuntu-latest