Skip to content

ci: set minimal GITHUB_TOKEN permissions on build-docs workflow#21

Merged
jimisola merged 3 commits into
mainfrom
fix/build-docs-permissions
Apr 19, 2026
Merged

ci: set minimal GITHUB_TOKEN permissions on build-docs workflow#21
jimisola merged 3 commits into
mainfrom
fix/build-docs-permissions

Conversation

@jimisola
Copy link
Copy Markdown
Member

Summary

Add workflow-level permissions: contents: read to .github/workflows/build-docs.yml to resolve the outstanding CodeQL alert (actions/missing-workflow-permissions, alert #1).

The reused workflow reqstool/.github/.github/workflows/build-docs.yml@main only reads the repo to build docs, so contents: read is sufficient. Matches the pattern already in validate-plugins.yml.

Test plan

Resolve CodeQL alert #1 (actions/missing-workflow-permissions) by
adding a workflow-level `permissions: contents: read` block. Matches
the pattern already used in validate-plugins.yml.

Signed-off-by: Jimisola Laursen <jimisola@jimisola.com>
@jimisola jimisola self-assigned this Apr 19, 2026
@jimisola jimisola merged commit e0f5cc4 into main Apr 19, 2026
3 checks passed
@jimisola jimisola deleted the fix/build-docs-permissions branch April 19, 2026 09:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant