From b64f6810810919779c378256a2c2914387159d12 Mon Sep 17 00:00:00 2001 From: Wyatt Murray <113722636+Skyfall1235@users.noreply.github.com> Date: Tue, 2 Dec 2025 09:19:20 -0500 Subject: [PATCH 1/2] Potential fix for code scanning alert no. 1: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/CodeQL_PR_Analysis.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/CodeQL_PR_Analysis.yml b/.github/workflows/CodeQL_PR_Analysis.yml index 282b240..0c9ca24 100644 --- a/.github/workflows/CodeQL_PR_Analysis.yml +++ b/.github/workflows/CodeQL_PR_Analysis.yml @@ -1,4 +1,7 @@ name: "CodeQL PR Analysis" +permissions: + contents: read + security-events: write on: pull_request: From 1e49ad979350900ca0ea74f2b0ff5a496dc25bf3 Mon Sep 17 00:00:00 2001 From: Wyatt Murray <113722636+Skyfall1235@users.noreply.github.com> Date: Tue, 2 Dec 2025 09:23:41 -0500 Subject: [PATCH 2/2] Upgrade CodeQL actions to version 3 Updated CodeQL actions to use version 3. --- .github/workflows/CodeQL_PR_Analysis.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/CodeQL_PR_Analysis.yml b/.github/workflows/CodeQL_PR_Analysis.yml index 0c9ca24..519eb2a 100644 --- a/.github/workflows/CodeQL_PR_Analysis.yml +++ b/.github/workflows/CodeQL_PR_Analysis.yml @@ -17,14 +17,14 @@ jobs: uses: actions/checkout@v3 - name: Initialize CodeQL - uses: github/codeql-action/init@v2 + uses: github/codeql-action/init@v3 with: languages: csharp # Using default queries (security + quality) # You can also specify custom queries if needed - name: Autobuild - uses: github/codeql-action/autobuild@v2 + uses: github/codeql-action/autobuild@v3 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v2 + uses: github/codeql-action/analyze@v3