Skip to content

Harden lint workflow token permissions to resolve CodeQL alert - #405

Merged
TorstenDittmann merged 2 commits into
mainfrom
copilot/fix-code-scanning-alerts-again
Aug 21, 2026
Merged

TorstenDittmann merged 2 commits into
mainfrom
copilot/fix-code-scanning-alerts-again

Conversation

Copilot AI commented Aug 21, 2026 •

Copy link
Copy Markdown
Contributor

This PR addresses the code scanning finding on GitHub Actions workflow permissions by removing reliance on inherited GITHUB_TOKEN defaults. It applies explicit least-privilege permissions in the affected workflow.

  • Problem addressed

    • Code scanning flagged .github/workflows/lint.yml for missing explicit workflow permissions (actions/missing-workflow-permissions), which can allow broader token scope than intended.
  • Change made

    • Added a workflow-level permissions block to constrain token access to read-only repository contents.
  • Resulting workflow config

    permissions:
        contents: read

Co-authored-by: TorstenDittmann <1759475+TorstenDittmann@users.noreply.github.com>
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Deploying svelte-markdoc-preprocess with  Cloudflare Pages  Cloudflare Pages

Latest commit: d54f570
Status: ✅  Deploy successful!
Preview URL: https://237f6b28.svelte-markdoc-preprocess.pages.dev
Branch Preview URL: https://copilot-fix-code-scanning-al-fap1.svelte-markdoc-preprocess.pages.dev

View logs

Copilot AI changed the title [WIP] Fix code scanning alert #9 Harden lint workflow token permissions to resolve CodeQL alert Aug 21, 2026
Copilot AI requested a review from TorstenDittmann August 21, 2026 13:58
@TorstenDittmann
TorstenDittmann marked this pull request as ready for review August 21, 2026 14:12
@TorstenDittmann
TorstenDittmann merged commit 4a653d1 into main Aug 21, 2026
14 checks passed
@TorstenDittmann
TorstenDittmann deleted the copilot/fix-code-scanning-alerts-again branch August 21, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants