Problem
Two open code-scanning alerts (actions/missing-workflow-permissions, #1 on .github/workflows/CI.yaml and #2 on .github/workflows/CD.yaml, both at line 9). Neither workflow declares a top-level permissions: block, so their GITHUB_TOKEN inherits the repo default (often read/write) instead of least privilege. docs.yml already sets permissions: contents: read and can serve as the pattern.
Proposed fix & acceptance
- Add an explicit top-level
permissions: block to CI.yaml (contents: read is sufficient — it only checks out and runs tests).
- Add a top-level
permissions: block to CD.yaml; it creates a git tag + GitHub release, so it needs contents: write (widen per-job only if needed) plus whatever the release action requires. Keep it as narrow as the publish flow allows.
- Acceptance: both code-scanning alerts resolve (zero open), workflows still run green.
Blast radius
safe (workflow metadata only; verify CD still has permission to tag/release).
Depends on
nothing
Problem
Two open code-scanning alerts (
actions/missing-workflow-permissions, #1 on.github/workflows/CI.yamland #2 on.github/workflows/CD.yaml, both at line 9). Neither workflow declares a top-levelpermissions:block, so theirGITHUB_TOKENinherits the repo default (often read/write) instead of least privilege.docs.ymlalready setspermissions: contents: readand can serve as the pattern.Proposed fix & acceptance
permissions:block toCI.yaml(contents: readis sufficient — it only checks out and runs tests).permissions:block toCD.yaml; it creates a git tag + GitHub release, so it needscontents: write(widen per-job only if needed) plus whatever the release action requires. Keep it as narrow as the publish flow allows.Blast radius
safe (workflow metadata only; verify CD still has permission to tag/release).
Depends on
nothing