Skip to content

ci: fix code scanning alerts#318

Closed
rootulp wants to merge 5 commits into
celestiaorg:mainfrom
rootulp:fix/code-scanning-alerts
Closed

ci: fix code scanning alerts#318
rootulp wants to merge 5 commits into
celestiaorg:mainfrom
rootulp:fix/code-scanning-alerts

Conversation

@rootulp

@rootulp rootulp commented Apr 14, 2026

Copy link
Copy Markdown
Collaborator

Summary

Test plan

  • CI workflows still pass (no functional changes, only permissions and ref pinning)
  • Verify code scanning alerts move to "fixed" state after merge

🤖 Generated with Claude Code

rootulp and others added 4 commits April 14, 2026 12:40
Add top-level permissions with contents:read to follow least-privilege
principle. Pin technote-space/get-diff-action, golangci/golangci-lint-action,
and celestiaorg/.github markdown-lint to commit SHAs.

Resolves code scanning alerts celestiaorg#5, celestiaorg#10, celestiaorg#21, celestiaorg#23, celestiaorg#24.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Resolves code scanning alert celestiaorg#22.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Pin bufbuild/buf-setup-action, buf-breaking-action, and buf-lint-action.

Resolves code scanning alerts celestiaorg#6, celestiaorg#7, celestiaorg#11.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add top-level permissions with contents:read. Pin bufbuild/buf-setup-action
and bufbuild/buf-push-action to commit SHAs.

Resolves code scanning alerts celestiaorg#9, celestiaorg#12, celestiaorg#20.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@rootulp rootulp self-assigned this Apr 14, 2026
@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

Accept upstream's actions/checkout@v6 and golangci-lint-action@v9 bumps
while keeping pinned commit SHAs for all 3rd-party actions.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@rootulp rootulp closed this Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant