Skip to content

Potential fix for code scanning alert no. 1: Workflow does not contain permissions - #14

Merged
corvid-agent merged 1 commit into
mainfrom
alert-autofix-1
Mar 19, 2026
Merged

Potential fix for code scanning alert no. 1: Workflow does not contain permissions#14
corvid-agent merged 1 commit into
mainfrom
alert-autofix-1

Conversation

@corvid-agent

Copy link
Copy Markdown
Collaborator

Potential fix for https://github.com/CorvidLabs/spec-sync/security/code-scanning/1

In general, the fix is to declare a permissions block that grants only the scopes needed by this workflow. Since the jobs only need to read the repository contents (for checkout) and do not interact with issues, PRs, or releases, contents: read at the workflow or job level is sufficient.

The best fix without changing functionality is to add a top-level permissions block just under the name: CI line in .github/workflows/ci.yml. This will apply to all jobs (test and fmt) and restrict the GITHUB_TOKEN to read-only repository contents. No other permissions (like pull-requests: write) are needed, since this workflow does not modify PRs or push changes. No additional imports, methods, or definitions are required; the change is purely declarative in the YAML.

Concretely, in .github/workflows/ci.yml, insert:

permissions:
  contents: read

between the name: CI line and the on: block (lines 1–3 in the snippet). All existing steps remain unchanged.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@corvid-agent
corvid-agent marked this pull request as ready for review March 19, 2026 01:04
@corvid-agent
corvid-agent merged commit 2d7cac9 into main Mar 19, 2026
7 checks passed
@corvid-agent
corvid-agent deleted the alert-autofix-1 branch March 19, 2026 01:10
0xLeif added a commit that referenced this pull request Aug 1, 2026
CI failed on checks we should have run before push:

- cargo fmt (rustfmt whitespace on helpers/tests)
- spec-check path coverage (need delivering active change + export docs)
- cascade: Required CI gate / implementation ready / trust

This commit:

- Formats sources
- Documents artifacts_complete_for_guidance
- Adds approved implementing CHG-0073 covering changed paths/specs
- Notes SpecSync 6 vs fledge#506 / #481 stranded-accepted UX

Local verify: cargo fmt --check, unit tests for #14/#16,
specsync check --strict --require-coverage 100 --force (exit 0).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant