From c9b5668a58091d4390bd6f79fce8c2abe58bc327 Mon Sep 17 00:00:00 2001 From: Richard Kindler <223166946+RickCreator87@users.noreply.github.com> Date: Sat, 7 Mar 2026 12:46:13 -0700 Subject: [PATCH] Potential fix for code scanning alert no. 1: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/catalog-sync.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/catalog-sync.yml b/.github/workflows/catalog-sync.yml index 94cfdd8..e89415e 100644 --- a/.github/workflows/catalog-sync.yml +++ b/.github/workflows/catalog-sync.yml @@ -6,6 +6,8 @@ on: jobs: sync: runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Sync metadata run: node scripts/sync-catalog.js