Skip to content

Commit 31639fb

Browse files
chrisdpurcellclaude
andcommitted
fix: add explicit permissions to workflow jobs (CodeQL)
Adds `permissions: contents: read` to both validate-hacs and validate-hassfest jobs. GitHub's default GITHUB_TOKEN permissions are broad; declaring minimal permissions follows least-privilege and resolves the CodeQL actions/missing-workflow-permissions medium alerts. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 171a35e commit 31639fb

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

.github/workflows/validate.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,8 @@ jobs:
1313
validate-hacs:
1414
name: HACS Validation
1515
runs-on: ubuntu-latest
16+
permissions:
17+
contents: read
1618
steps:
1719
- uses: actions/checkout@v4
1820
- name: HACS Validation
@@ -23,6 +25,8 @@ jobs:
2325
validate-hassfest:
2426
name: Hassfest Validation
2527
runs-on: ubuntu-latest
28+
permissions:
29+
contents: read
2630
steps:
2731
- uses: actions/checkout@v4
2832
- name: Hassfest Validation

0 commit comments

Comments
 (0)