Skip to content

Potential fix for code scanning alert no. 2: Workflow does not contain permissions - #225

Merged
ejscribner merged 1 commit into
mainfrom
alert-autofix-2
Sep 30, 2026
Merged

ejscribner merged 1 commit into
mainfrom
alert-autofix-2

Conversation

@ejscribner

Copy link
Copy Markdown
Contributor

Potential fix for https://github.com/couchbase-examples/nextjs-capella-quickstart/security/code-scanning/2

Add an explicit permissions block in .github/workflows/ci.yaml at the workflow root (top-level), so it applies to all jobs unless overridden. The least-privilege fix that preserves current behavior is:

  • contents: read

This supports actions/checkout and avoids unnecessary write access for GITHUB_TOKEN. No imports, methods, or dependencies are needed; this is a YAML configuration-only change.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…n permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
nextjs-capella-quickstart Ready Ready Preview Sep 30, 2026 3:39pm UTC

@ejscribner

Copy link
Copy Markdown
Contributor Author

@dex-the-ai can you review this one for me?

@dex-the-ai

Copy link
Copy Markdown
Contributor

@ejscribner Reviewed. Looks good to merge. 👍

What changed: a top-level permissions: contents: read block in .github/workflows/ci.yaml. It limits the GITHUB_TOKEN for the only job (run_tests) to read access, which resolves CodeQL alert #2 (actions/missing-workflow-permissions).

Will the job still work with read-only access? Yes. I went through each step:

  • actions/checkout@v7: only needs contents: read.
  • actions/setup-node@v7, npm install, npm test: don't use the token.
  • ravsamhq/notify-slack-action@v2: posts through SLACK_WEBHOOK_URL. Its optional token input is only used to look up workflow URLs, and this workflow doesn't pass it, so the reduced scope doesn't affect it.
  • The Capella credentials come from vars and secrets, which permissions doesn't control.

Checks on this PR: Run Tests, both CodeQL analyses, and the Vercel preview all passed with the new block in place. That means the restricted token worked in a real run.

Notes (neither blocks merging):

  • The alert will still show as open until this merges into main, because it's tracked against the default branch.
  • This is the only workflow file in the repo, so no other workflow is missing a permissions block.

@ejscribner
ejscribner merged commit d9f22ab into main Sep 30, 2026
6 checks passed
@ejscribner
ejscribner deleted the alert-autofix-2 branch September 30, 2026 15:58

This branch was successfully deployed

1 active deployment
Preview — 1962230f Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants