Skip to content

Potential fix for code scanning alert no. 3: Workflow does not contain permissions - #6

Merged
Lawrence Lucas Large (LukeLarge) merged 1 commit into
masterfrom
alert-autofix-3
Dec 3, 2025
Merged

Lawrence Lucas Large (LukeLarge) merged 1 commit into
masterfrom
alert-autofix-3

Conversation

@LukeLarge

Copy link
Copy Markdown
Collaborator

Potential fix for https://github.com/LukeLarge/opentonapi/security/code-scanning/3

The best way to fix this issue is to explicitly define the minimal permissions the workflow needs by adding a permissions block at either the workflow or job level. Since this workflow is likely to open pull requests (according to its name and apparent logic—make update-sdk is likely to include creating a PR), the minimal necessary permissions should be contents: read and pull-requests: write. The optimal way to implement this is to add a permissions: block at the top level, beneath the name field but above jobs, to ensure all jobs inherit the correct permissions. No additional imports or code definitions are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

potential fix for no permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@LukeLarge
Lawrence Lucas Large (LukeLarge) marked this pull request as ready for review December 3, 2025 18:27
Copilot AI review requested due to automatic review settings December 3, 2025 18:27
@LukeLarge
Lawrence Lucas Large (LukeLarge) merged commit 6e2b86c into master Dec 3, 2025
5 of 7 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses a code scanning alert by adding a permissions block to the GitHub Actions workflow that creates pull requests for TonAPI SDK updates. While the addition of explicit permissions is a security best practice, the specified permission level is incorrect for the workflow's operations.

  • Adds workflow-level permissions block to restrict token access
  • Sets contents: read and pull-requests: write permissions

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@@ -1,4 +1,7 @@
name: Create a pull request to update TonAPI SDK
permissions:
contents: read

Copilot AI Dec 3, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The contents: read permission is insufficient for this workflow. The make update-sdk command (line 19) performs a git push -u origin update -f operation (see Makefile line 34), which requires write access to the repository contents. The permission should be contents: write instead of contents: read.

Suggested change
contents: read
contents: write

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants