From 278e74d53fe56d22a312e25c8d59504e368d9a50 Mon Sep 17 00:00:00 2001 From: Toni Bergholm Date: Fri, 22 May 2026 17:41:21 +0300 Subject: [PATCH] ci: add permissions: contents: read to satisfy CodeQL workflow-permissions alerts Three CodeQL Medium alerts flagged that the workflow had no explicit permissions block, leaving jobs with the default (which can be write-all on some orgs). Pinning to contents: read at the workflow level closes all three alerts and follows GitHub's principle-of-least-privilege guidance for CI workflows. --- .github/workflows/ci.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9f4bb28..b6b0942 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,6 +5,9 @@ on: branches: [main] pull_request: +permissions: + contents: read + env: CARGO_TERM_COLOR: always RUSTFLAGS: "-D warnings"