Skip to content

Potential fix for code scanning alert no. 1: Workflow does not contain permissions - #4

Merged
apannetrat merged 1 commit into
mainfrom
alert-autofix-1
Sep 28, 2026
Merged

apannetrat merged 1 commit into
mainfrom
alert-autofix-1

Conversation

@apannetrat

Copy link
Copy Markdown
Contributor

Potential fix for https://github.com/CloudSecurityAlliance/CSA-Component-Library/security/code-scanning/1

Add an explicit permissions block to .github/workflows/check-asset-filenames.yml so the workflow token is constrained to only what this job needs.
Best fix without changing functionality: add workflow-level permissions with contents: read right after the on: triggers (or before jobs:). This preserves behavior (checkout/read operations still work) while preventing unnecessary write scopes.

Only one file/region needs updating:

  • File: .github/workflows/check-asset-filenames.yml
  • Change: insert:
    permissions:
      contents: read
    above jobs:.

No imports, methods, or dependencies are needed.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@apannetrat
apannetrat marked this pull request as ready for review September 28, 2026 15:11
@apannetrat
apannetrat merged commit e1fe31e into main Sep 28, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant