fix(ci): restrict GITHUB_TOKEN to contents:read via explicit permissions block

GitHub Advanced Security flagged that the workflow had no permissions block,
leaving GITHUB_TOKEN with its default broad scope. All write operations
(git push, gh pr create) already use GH_TOKEN (PAT), so the implicit
GITHUB_TOKEN only needs read access.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Julio Quinteros Pro 2026-02-19 19:24:57 -03:00
parent 5681229e7c
commit b9e79cc07b

View file

@ -11,6 +11,9 @@ on:
- pyproject.toml
workflow_dispatch:
permissions:
contents: read # GITHUB_TOKEN is not used for writes; GH_TOKEN (PAT) handles push + PR creation
jobs:
regenerate-lock:
runs-on: ubuntu-latest