Repository navigation
Conversation
…r delivery strategy, tune QUIC flow control
…tale share group counters
| runs-on: ubuntu-latest | ||
| name: Paper Draft | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| - name: Build draft PDF | ||
| uses: openjournals/openjournals-draft-action@master | ||
| with: | ||
| journal: joss | ||
| paper-path: joss/paper.md | ||
| - name: Upload | ||
| uses: actions/upload-artifact@v4 | ||
| with: | ||
| name: paper | ||
| path: joss/paper.pdf |
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 7 months ago
In general, the fix is to add an explicit permissions block to the workflow or the specific job, granting only the minimal scopes required. For this workflow, the actions used (actions/checkout, openjournals/openjournals-draft-action, and actions/upload-artifact) only need read access to repository contents; they do not need to write to the repository or modify issues, PRs, etc. Therefore, the safest and simplest change is to add permissions: contents: read at the job level for paper.
Concretely, in .github/workflows/joss.yml, under jobs: paper: and aligned with runs-on / name, add:
permissions:
contents: readThis will restrict the GITHUB_TOKEN used in that job to read-only repository contents, without altering the workflow’s behavior. No additional methods, imports, or other definitions are needed because this is purely a YAML configuration change.
| @@ -9,6 +9,8 @@ | ||
| paper: | ||
| runs-on: ubuntu-latest | ||
| name: Paper Draft | ||
| permissions: | ||
| contents: read | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 |
Summary
joss/paper.md,joss/paper.bib) and CODE_OF_CONDUCT.mdTest plan