From 7204c7649b9849151bda4833cc4cdf52e325bea8 Mon Sep 17 00:00:00 2001 From: Jim W Date: Mon, 15 Dec 2025 12:28:29 -0500 Subject: [PATCH 1/3] Potential fix for code scanning alert no. 1: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/test.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 7ff68cc..78158db 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -1,4 +1,6 @@ name: Build and Test +permissions: + contents: read on: [pull_request] From a5f544a336751ffb8a00a3ff041c7bb1c653ee64 Mon Sep 17 00:00:00 2001 From: Jim W Date: Mon, 15 Dec 2025 12:29:12 -0500 Subject: [PATCH 2/3] Potential fix for code scanning alert no. 2: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/golangci_lint.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/golangci_lint.yml b/.github/workflows/golangci_lint.yml index a03a451..0292a44 100644 --- a/.github/workflows/golangci_lint.yml +++ b/.github/workflows/golangci_lint.yml @@ -5,6 +5,8 @@ on: [pull_request] jobs: detect-modules: runs-on: ubuntu-latest + permissions: + contents: read outputs: modules: ${{ steps.set-modules.outputs.modules }} steps: From bd5b74c8ad9c7663f15465baf38de16d82f0fcae Mon Sep 17 00:00:00 2001 From: Jim W Date: Mon, 15 Dec 2025 12:31:03 -0500 Subject: [PATCH 3/3] Potential fix for code scanning alert no. 4: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/ci-protobuf.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/ci-protobuf.yml b/.github/workflows/ci-protobuf.yml index 4a1c805..b2c42cd 100644 --- a/.github/workflows/ci-protobuf.yml +++ b/.github/workflows/ci-protobuf.yml @@ -1,5 +1,7 @@ name: CI ProtoBuf +permissions: + contents: read on: pull_request: