Skip to content

Conversation

@joeyguerra
Copy link
Member

Potential fix for https://github.com/hubot-friends/hubot-service-discovery/security/code-scanning/1

The best way to fix this problem is to explicitly set the minimal required permissions for the test job in the workflow file. Add a permissions block under the test job, before or after runs-on, specifying contents: read. This limits the GitHub token to only read contents, which is appropriate for CI jobs that only test or build code and do not need to make any modifications to the repository or interact with issues, pull requests, or other writable resources. No new methods, imports, or additions are required outside of this YAML change.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@joeyguerra joeyguerra marked this pull request as ready for review September 20, 2025 21:16
@joeyguerra joeyguerra merged commit d5101bc into main Sep 20, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant