From 71ebdd9d3cf8d9e185794d2e8dc61cd6c8725727 Mon Sep 17 00:00:00 2001 From: Jiaren Wu Date: Mon, 13 Oct 2025 10:38:14 -0700 Subject: [PATCH] Potential fix for code scanning alert no. 3: Workflow does not contain permissions (#4273) Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/arc-update-runners-scheduled.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/arc-update-runners-scheduled.yaml b/.github/workflows/arc-update-runners-scheduled.yaml index ed083097..424c5e82 100644 --- a/.github/workflows/arc-update-runners-scheduled.yaml +++ b/.github/workflows/arc-update-runners-scheduled.yaml @@ -50,6 +50,8 @@ jobs: # it sets a PR name as output. check_pr: runs-on: ubuntu-latest + permissions: + contents: read needs: check_versions if: needs.check_versions.outputs.runner_current_version != needs.check_versions.outputs.runner_latest_version || needs.check_versions.outputs.container_hooks_current_version != needs.check_versions.outputs.container_hooks_latest_version outputs: