Title: Specify explicit `contents: read` workflow permissions by EliahKagan · Pull Request #2033 · gitpython-developers/GitPython · GitHub
Open Graph Title: Specify explicit `contents: read` workflow permissions by EliahKagan · Pull Request #2033 · gitpython-developers/GitPython
X Title: Specify explicit `contents: read` workflow permissions by EliahKagan · Pull Request #2033 · gitpython-developers/GitPython
Description: Specify explicit contents: read workflow permissions Three CI workflows that need only contents: read permissions and no other permissions did not have explicit permissions set, and would therefore be given default permissions configured for the repository, which might be more expansive than the workflows need. It is recommended to set explicit workflow permissions. This does that, specifying permissions as pythonpackage.yml already did, and closing three actions/missing-workflow-permissions CodeQL alerts (new since #2032 enabled scanning of GHA workflows). I'll merge this once I verify that all CI checks still pass.
Open Graph Description: Specify explicit contents: read workflow permissions Three CI workflows that need only contents: read permissions and no other permissions did not have explicit permissions set, and would therefore...
X Description: Specify explicit contents: read workflow permissions Three CI workflows that need only contents: read permissions and no other permissions did not have explicit permissions set, and would therefore...
Opengraph URL: https://github.com/gitpython-developers/GitPython/pull/2033
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:dce7136a-1bc5-aac2-f15a-23e9d0cf8be1 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | 9242:1E3377:968EA5:C92AD9:6968391F |
| html-safe-nonce | 5a3acdfb00e266f1ecba3a46f64fe235c27eecc7f0e53f5eb4a3d38d2645681d |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5MjQyOjFFMzM3Nzo5NjhFQTU6QzkyQUQ5OjY5NjgzOTFGIiwidmlzaXRvcl9pZCI6Ijc2NjIyMjA4MDMxMzM5NDYxNDMiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | cfebf9fdf27320c8a6d3b91c4cc5c0c377f0a8be0a9050402f404ef907300a25 |
| hovercard-subject-tag | pull_request:2555546869 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/gitpython-developers/GitPython/pull/2033/files |
| twitter:image | https://avatars.githubusercontent.com/u/1771172?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/1771172?s=400&v=4 |
| og:image:alt | Specify explicit contents: read workflow permissions Three CI workflows that need only contents: read permissions and no other permissions did not have explicit permissions set, and would therefore... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | e25f416bb6d8a5f8624aad6cebc375ab2c50ac58f2175f32a7093325e66e5515 |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/gitpython-developers/GitPython git https://github.com/gitpython-developers/GitPython.git |
| octolytics-dimension-user_id | 503709 |
| octolytics-dimension-user_login | gitpython-developers |
| octolytics-dimension-repository_id | 1126087 |
| octolytics-dimension-repository_nwo | gitpython-developers/GitPython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1126087 |
| octolytics-dimension-repository_network_root_nwo | gitpython-developers/GitPython |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 32212b8b3bddd6432b3b35d27c050b1c22bd8cca |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width