-
Notifications
You must be signed in to change notification settings - Fork 330
Fix scan issues #2202
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix scan issues #2202
Conversation
Signed-off-by: ZePan110 <ze.pan@intel.com>
Dependency Review✅ No vulnerabilities or license issues found.Scanned FilesNone |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull Request Overview
This PR addresses scan-related issues in GitHub workflow files by standardizing permission configurations and environment variable usage. The changes appear to be security and best practice improvements to GitHub Actions workflows.
Key changes:
- Refactored environment variable usage in hyperlink and path validation workflows
- Adjusted GitHub Actions permissions across multiple workflow files
- Moved job-level permissions to workflow-level where appropriate
Reviewed Changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/pr-link-path-scan.yml |
Moved inline GitHub context variables to environment variables for better security |
.github/workflows/pr-code-scan.yml |
Changed security-events permission from write to read |
.github/workflows/nightly-docker-build-publish.yml |
Removed packages write permission |
.github/workflows/manual-image-build.yml |
Removed multiple unnecessary permissions (checks, deployments, packages, statuses) |
.github/workflows/manual-example-workflow.yml |
Removed multiple unnecessary permissions (checks, deployments, packages, statuses) |
.github/workflows/daily_check_issue_and_pr.yml |
Moved permissions from job level to workflow level |
.github/workflows/daily-update-vllm-version.yml |
Moved permissions from job level to workflow level |
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
for more information, see https://pre-commit.ci
Signed-off-by: ZePan110 <ze.pan@intel.com>
…nAIExamples into ze-fix/scan-cont Signed-off-by: ZePan110 <ze.pan@intel.com>
Description
Fix scan issues
Issues
List the issue or RFC link this PR is working on. If there is no such link, please mark it as
n/a.Type of change
List the type of change like below. Please delete options that are not relevant.
Dependencies
List the newly introduced 3rd party dependency if exists.
Tests
nightly-docker-build-publish.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981292565
pr-code-scan.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981250289
pr-link-path-scan.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981250300
daily-update-vllm-version.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981340575/job/48141680539
manual-example-workflow.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981386837
manual-image-build.yml
https://github.com/opea-project/GenAIExamples/actions/runs/16981416514