From 6b452e706f6f84f16046d330cda45b4d8e603613 Mon Sep 17 00:00:00 2001 From: Kristjan ESPERANTO <35647502+KristjanESPERANTO@users.noreply.github.com> Date: Sun, 19 Apr 2026 19:01:04 +0200 Subject: [PATCH] ci(actions): set explicit token permissions Add minimal GITHUB_TOKEN permissions to electron-rebuild workflow to enforce least privilege and satisfy CodeQL alert #14. --- .github/workflows/electron-rebuild.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/electron-rebuild.yaml b/.github/workflows/electron-rebuild.yaml index e9cad3346c..dd30f538c7 100644 --- a/.github/workflows/electron-rebuild.yaml +++ b/.github/workflows/electron-rebuild.yaml @@ -1,5 +1,8 @@ name: "Electron Rebuild Testing" +permissions: + contents: read + on: [pull_request] jobs: