From c9de59a9e33db7ac99ca4d5698ac81a11790187a Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 24 Dec 2025 22:31:16 +0000 Subject: [PATCH] Add explicit permissions for workflow security Set minimal read-only permissions for GITHUB_TOKEN to follow security best practices and fix CodeQL alert. Co-authored-by: johndoe6345789 <224850594+johndoe6345789@users.noreply.github.com> --- .github/workflows/cpp-build.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/cpp-build.yml b/.github/workflows/cpp-build.yml index b272bb9db..a4fe04c10 100644 --- a/.github/workflows/cpp-build.yml +++ b/.github/workflows/cpp-build.yml @@ -15,10 +15,15 @@ on: - '.github/workflows/cpp-build.yml' workflow_dispatch: +permissions: + contents: read + jobs: check-implementation: name: Check C++ Implementation Status runs-on: ubuntu-latest + permissions: + contents: read outputs: has_sources: ${{ steps.check.outputs.has_sources }} steps: