Skip to content

fix: add explicit permissions to CI workflow#7

Merged
lzhgus merged 1 commit intomainfrom
fix/ci-permissions
Apr 11, 2026
Merged

fix: add explicit permissions to CI workflow#7
lzhgus merged 1 commit intomainfrom
fix/ci-permissions

Conversation

@lzhgus
Copy link
Copy Markdown
Owner

@lzhgus lzhgus commented Apr 11, 2026

Summary

No functional changes — CI only needs to checkout code and run builds/tests.

Restrict GITHUB_TOKEN to contents:read in ci.yml to follow the
principle of least privilege. Resolves CodeQL code-scanning alert.
@lzhgus lzhgus merged commit b2d680e into main Apr 11, 2026
5 checks passed
@lzhgus lzhgus deleted the fix/ci-permissions branch April 11, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant