mirror of
https://github.com/suitenumerique/drive.git
synced 2026-04-25 17:15:19 +02:00
CodeQL flagged the workflow for running with default GITHUB_TOKEN permissions. None of the jobs need write scopes, so pin to the minimum to contain blast radius if a third-party action is compromised.