Skip to content

Conversation

@jperals
Copy link
Member

@jperals jperals commented Jul 25, 2025

Potential fix for https://github.com/cloudscape-design/chart-components/security/code-scanning/3

To fix the problem, add an explicit permissions block to the workflow file. This block should specify the minimal permissions required for each job. For example:

  • For the test job, it likely only requires contents: read since it primarily checks out the repository, installs dependencies, runs tests, and downloads/upload artifacts.
  • For the update job, it may need contents: write to update snapshots.

The permissions block should be added at the job level to ensure different permissions for test and update jobs. This ensures each job only has access to what it needs.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@jperals jperals changed the title Potential fix for code scanning alert no. 3: Workflow does not contain permissions fix: Add explicit permissions to visual regression workflow Jul 25, 2025
@jperals jperals marked this pull request as ready for review August 4, 2025 08:52
@jperals jperals requested a review from pan-kot as a code owner August 4, 2025 08:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants