From ae8744ff0f61a8b2d3cbb0914dcdb4df86a7bf01 Mon Sep 17 00:00:00 2001 From: Bill Forney Date: Sat, 14 Jun 2025 02:10:51 -0700 Subject: [PATCH] Potential fix for code scanning alert no. 50: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/release.yml | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ee131f2..eaa20aa 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -3,11 +3,16 @@ name: .NET Continuous Deployment on: workflow_dispatch: +permissions: + contents: read + jobs: test: name: SharedCode Test runs-on: windows-latest + permissions: + contents: read steps: - uses: actions/checkout@v3 @@ -23,6 +28,8 @@ jobs: needs: test name: Create a Package Release runs-on: windows-latest + permissions: + contents: write steps: - uses: actions/checkout@v3 @@ -57,6 +64,8 @@ jobs: needs: semantic-release name: Publish to Github runs-on: windows-latest + permissions: + packages: write steps: - name: Download built project uses: actions/download-artifact@v4.1.8 @@ -75,6 +84,8 @@ jobs: needs: semantic-release name: Publish to Nuget runs-on: windows-latest + permissions: + packages: write steps: - name: Download built project uses: actions/download-artifact@v4.1.8