Fixes for code scanning alerts: Workflow does not contain permissions #60
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Potential fix for https://github.com/hugetim/nbstata/security/code-scanning/1
To fix the issue, we need to add a
permissionsblock that restricts the permissions of the GITHUB_TOKEN for this workflow/job. Since the job appears to run tests viafastai/workflows/nbdev-ci@master, the minimal permissions required are typicallycontents: read. If the workflow requires writing pull requests or issues (to provide feedback or status), then you can increase those permissions, but the minimal safe starting point iscontents: read. The most direct way is to insert this block either at the root (applies to all jobs) or at the job level. Insert after theon:statement, beforejobs:.Suggested fixes powered by Copilot Autofix. Review carefully before merging.