Commit 31639fb
fix: add explicit permissions to workflow jobs (CodeQL)
Adds `permissions: contents: read` to both validate-hacs and
validate-hassfest jobs. GitHub's default GITHUB_TOKEN permissions are
broad; declaring minimal permissions follows least-privilege and
resolves the CodeQL actions/missing-workflow-permissions medium alerts.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 171a35e commit 31639fb
1 file changed
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
| 17 | + | |
16 | 18 | | |
17 | 19 | | |
18 | 20 | | |
| |||
23 | 25 | | |
24 | 26 | | |
25 | 27 | | |
| 28 | + | |
| 29 | + | |
26 | 30 | | |
27 | 31 | | |
28 | 32 | | |
| |||
0 commit comments