From 51a4ce35a37ad643e7b2308a66b00aac3afd92f2 Mon Sep 17 00:00:00 2001 From: Jeffrey Paul Date: Wed, 4 Feb 2026 17:08:56 -0600 Subject: [PATCH 1/2] Potential fix for code scanning alert no. 1: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/build.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 8b9c2a8..4b489cd 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -9,6 +9,8 @@ on: jobs: build_push_to_dockerhub: + permissions: + contents: read strategy: matrix: base_container: ["php:7.4-bullseye", "php:8.0-bullseye", "php:8.1-bullseye", "php:8.2-bullseye", "php:8.3-bullseye"] From 17cd239ca2407fe88439daacd303a97c1ecb0a9c Mon Sep 17 00:00:00 2001 From: Jeffrey Paul Date: Wed, 4 Feb 2026 17:10:53 -0600 Subject: [PATCH 2/2] Update build.yaml --- .github/workflows/build.yaml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 4b489cd..808c808 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -1,5 +1,8 @@ name: Build Docker image +permissions: + contents: read + on: push: branches: @@ -9,8 +12,6 @@ on: jobs: build_push_to_dockerhub: - permissions: - contents: read strategy: matrix: base_container: ["php:7.4-bullseye", "php:8.0-bullseye", "php:8.1-bullseye", "php:8.2-bullseye", "php:8.3-bullseye"]