Skip to content

Commit 5ab5874

Browse files
authored
Merge branch 'develop' into hxia/sec-policy
2 parents 6d49617 + b755b96 commit 5ab5874

4 files changed

Lines changed: 16 additions & 3 deletions

File tree

.github/workflows/code-quality.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: Code Quality
22

33
on: [push, pull_request]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
code-quality:
710
name: Code Quality Checks

.github/workflows/npm-release.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,13 +9,18 @@ on:
99
paths:
1010
- 'libCacheSim-node/**'
1111

12+
permissions:
13+
contents: read # Default permission for reading repository contents
14+
1215
env:
1316
BUILD_TYPE: Release
1417

1518
jobs:
1619
create-release:
1720
if: github.event_name == 'release'
1821
runs-on: ubuntu-latest
22+
permissions:
23+
contents: write # Needed for creating GitHub releases
1924
outputs:
2025
release_created: ${{ steps.release.outputs.release_created }}
2126
version: ${{ steps.package.outputs.version }}
@@ -79,6 +84,8 @@ jobs:
7984
if: github.event_name == 'release'
8085
needs: create-release
8186
runs-on: ubuntu-latest
87+
permissions:
88+
contents: write # Needed for uploading prebuilt binaries to releases
8289

8390
steps:
8491
- name: Checkout code

.github/workflows/scorecard.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,9 @@ on:
1515
branches: [ "develop" ]
1616

1717
# Declare default permissions as read only.
18-
permissions: read-all
18+
permissions:
19+
contents: read
20+
actions: read
1921

2022
jobs:
2123
analysis:

requirements.txt

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,3 @@
1-
numpy
2-
matplotlib
1+
# Core dependencies with security-patched versions
2+
numpy>=1.22.0 # CVE-2021-34141 fix (GHSA-fpfv-jqm9-f5jm)
3+
matplotlib>=3.3.0

0 commit comments

Comments
 (0)