Skip to content

Commit 88e3452

Browse files
committed
ci(rust): add explicit contents:read permissions
Addresses CodeQL workflow-permissions findings on rust.yml jobs (fmt, clippy, test, ts-bindings, build). Top-level block applies to every job since none of them need write access.
1 parent fbff8b8 commit 88e3452

1 file changed

Lines changed: 13 additions & 10 deletions

File tree

‎.github/workflows/rust.yml‎

Lines changed: 13 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -4,24 +4,27 @@ on:
44
push:
55
branches: [dev, main]
66
paths:
7-
- "crates/**"
8-
- "Cargo.toml"
9-
- "Cargo.lock"
10-
- "rust-toolchain.toml"
11-
- ".github/workflows/rust.yml"
7+
- 'crates/**'
8+
- 'Cargo.toml'
9+
- 'Cargo.lock'
10+
- 'rust-toolchain.toml'
11+
- '.github/workflows/rust.yml'
1212
pull_request:
1313
branches: [dev, main]
1414
paths:
15-
- "crates/**"
16-
- "Cargo.toml"
17-
- "Cargo.lock"
18-
- "rust-toolchain.toml"
19-
- ".github/workflows/rust.yml"
15+
- 'crates/**'
16+
- 'Cargo.toml'
17+
- 'Cargo.lock'
18+
- 'rust-toolchain.toml'
19+
- '.github/workflows/rust.yml'
2020

2121
concurrency:
2222
group: rust-${{ github.workflow }}-${{ github.ref }}
2323
cancel-in-progress: true
2424

25+
permissions:
26+
contents: read
27+
2528
env:
2629
CARGO_TERM_COLOR: always
2730
RUST_BACKTRACE: 1

0 commit comments

Comments
 (0)