From 4a653cb3e022c5829883e111d917acf31a075238 Mon Sep 17 00:00:00 2001 From: Paul Hodgkinson <41705651+aegilops@users.noreply.github.com> Date: Wed, 10 Dec 2025 14:32:36 +0000 Subject: [PATCH 1/2] Potential fix for code scanning alert no. 3: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/pr-markdown.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/pr-markdown.yml b/.github/workflows/pr-markdown.yml index 03842621..a01686b5 100644 --- a/.github/workflows/pr-markdown.yml +++ b/.github/workflows/pr-markdown.yml @@ -1,4 +1,6 @@ name: Markdown Validation +permissions: + contents: read on: pull_request: From 42d52af79df1a8443b7464e6e78b753a4c66e85a Mon Sep 17 00:00:00 2001 From: Paul Hodgkinson <41705651+aegilops@users.noreply.github.com> Date: Wed, 10 Dec 2025 14:34:43 +0000 Subject: [PATCH 2/2] Update PR markdown workflow permissions Added write permission for pull requests to the workflow. --- .github/workflows/pr-markdown.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/.github/workflows/pr-markdown.yml b/.github/workflows/pr-markdown.yml index a01686b5..f4239994 100644 --- a/.github/workflows/pr-markdown.yml +++ b/.github/workflows/pr-markdown.yml @@ -1,6 +1,7 @@ name: Markdown Validation permissions: contents: read + pull-requests: write on: pull_request: @@ -27,8 +28,6 @@ jobs: token: ${{ steps.get_workflow_token.outputs.token }} - name: Check git status - env: - GH_TOKEN: ${{ steps.get_workflow_token.outputs.token }} run: | if [ -z "$(git status --porcelain)" ]; then gh pr comment --edit-last ${{ github.event.number }} \