Skip to content

Security nits: read-only GITHUB_TOKEN for tests; docs typo fixes - #729

Open
tobixen wants to merge 2 commits into
masterfrom
ci-and-docs-fixes
Open

tobixen wants to merge 2 commits into
masterfrom
ci-and-docs-fixes

Conversation

@tobixen

@tobixen tobixen commented Oct 8, 2026

Copy link
Copy Markdown
Member

The tests workflow had no permissions block, so its jobs ran with the
repository's default token scope.  None of its steps need write
access.  Clears the code-scanning missing-workflow-permissions alerts.

Prompt: (...) also check if you can mitigate https://github.com/python-caldav/caldav/security/code-scanning/7 and its neighbours
Followup-Prompt: [publish the CI and docs fixups as PRs]

Assisted-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviewed-by: Tobias Brox <tobias@redpill-linpro.com>
Prompt: [fix review findings]

Assisted-By: Claude Opus 5.5 <noreply@anthropic.com>
Reviewed-by: Tobias Brox <tobias@redpill-linpro.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant