Commit e0d207e
committed
ci(qa): add least-privilege permissions block (contents: read)
Silences CodeQL actions/missing-workflow-permissions. The QA gate only reads
the tree (checkout + host scripts), so an explicit read-only token is correct
and defends in depth even if the repo default token scope changes.
Assisted-by: AI1 parent 1356a86 commit e0d207e
1 file changed
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
12 | 16 | | |
13 | 17 | | |
14 | 18 | | |
| |||
0 commit comments