Fix scan issues#2202
Merged
Merged
Conversation
Signed-off-by: ZePan110 <ze.pan@intel.com>
Dependency Review✅ No vulnerabilities or license issues found.Scanned FilesNone |
Contributor
There was a problem hiding this comment.
Pull Request Overview
This PR addresses scan-related issues in GitHub workflow files by standardizing permission configurations and environment variable usage. The changes appear to be security and best practice improvements to GitHub Actions workflows.
Key changes:
- Refactored environment variable usage in hyperlink and path validation workflows
- Adjusted GitHub Actions permissions across multiple workflow files
- Moved job-level permissions to workflow-level where appropriate
Reviewed Changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/pr-link-path-scan.yml |
Moved inline GitHub context variables to environment variables for better security |
.github/workflows/pr-code-scan.yml |
Changed security-events permission from write to read |
.github/workflows/nightly-docker-build-publish.yml |
Removed packages write permission |
.github/workflows/manual-image-build.yml |
Removed multiple unnecessary permissions (checks, deployments, packages, statuses) |
.github/workflows/manual-example-workflow.yml |
Removed multiple unnecessary permissions (checks, deployments, packages, statuses) |
.github/workflows/daily_check_issue_and_pr.yml |
Moved permissions from job level to workflow level |
.github/workflows/daily-update-vllm-version.yml |
Moved permissions from job level to workflow level |
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
for more information, see https://pre-commit.ci
Signed-off-by: ZePan110 <ze.pan@intel.com>
…nAIExamples into ze-fix/scan-cont Signed-off-by: ZePan110 <ze.pan@intel.com>
chensuyue
approved these changes
Aug 15, 2025
chensuyue
approved these changes
Aug 15, 2025
lvliang-intel
approved these changes
Aug 15, 2025
cogniware-devops
pushed a commit
to Cogniware-Inc/GenAIExamples
that referenced
this pull request
Dec 19, 2025
Signed-off-by: ZePan110 <ze.pan@intel.com> Signed-off-by: cogniware-devops <ambarish.desai@cogniware.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fix scan issues
Issues
List the issue or RFC link this PR is working on. If there is no such link, please mark it as
n/a.Type of change
List the type of change like below. Please delete options that are not relevant.
Dependencies
List the newly introduced 3rd party dependency if exists.
Tests
nightly-docker-build-publish.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981292565
pr-code-scan.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981250289
pr-link-path-scan.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981250300
daily-update-vllm-version.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981340575/job/48141680539
manual-example-workflow.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981386837
manual-image-build.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981416514