From e42623491dcf582c666dcaf1b3f36a84eb9cbea4 Mon Sep 17 00:00:00 2001 From: Jiaren Wu Date: Mon, 13 Oct 2025 10:09:50 -0700 Subject: [PATCH] Potential fix for code scanning alert no. 3: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/arc-update-runners-scheduled.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/arc-update-runners-scheduled.yaml b/.github/workflows/arc-update-runners-scheduled.yaml index ed083097..424c5e82 100644 --- a/.github/workflows/arc-update-runners-scheduled.yaml +++ b/.github/workflows/arc-update-runners-scheduled.yaml @@ -50,6 +50,8 @@ jobs: # it sets a PR name as output. check_pr: runs-on: ubuntu-latest + permissions: + contents: read needs: check_versions if: needs.check_versions.outputs.runner_current_version != needs.check_versions.outputs.runner_latest_version || needs.check_versions.outputs.container_hooks_current_version != needs.check_versions.outputs.container_hooks_latest_version outputs: