From b9e79cc07b1977fe9aa74d3280cbbb1a2081fff4 Mon Sep 17 00:00:00 2001 From: Julio Quinteros Pro Date: Thu, 19 Feb 2026 19:24:57 -0300 Subject: [PATCH] fix(ci): restrict GITHUB_TOKEN to contents:read via explicit permissions block GitHub Advanced Security flagged that the workflow had no permissions block, leaving GITHUB_TOKEN with its default broad scope. All write operations (git push, gh pr create) already use GH_TOKEN (PAT), so the implicit GITHUB_TOKEN only needs read access. Co-Authored-By: Claude Sonnet 4.6 --- .github/workflows/regenerate-poetry-lock.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/regenerate-poetry-lock.yml b/.github/workflows/regenerate-poetry-lock.yml index 83f53277ef8..7e4bac017df 100644 --- a/.github/workflows/regenerate-poetry-lock.yml +++ b/.github/workflows/regenerate-poetry-lock.yml @@ -11,6 +11,9 @@ on: - pyproject.toml workflow_dispatch: +permissions: + contents: read # GITHUB_TOKEN is not used for writes; GH_TOKEN (PAT) handles push + PR creation + jobs: regenerate-lock: runs-on: ubuntu-latest