Skip to content

Conversation

@mhucka
Copy link
Contributor

@mhucka mhucka commented Nov 4, 2025

Changes:

  1. Add a top-level default permissions declarations to ci.yml to address https://github.com/quantumlib/tesseract-decoder/security/code-scanning/4

  2. Add commit hashes to third-party workflow references that didn't have them to address https://github.com/quantumlib/tesseract-decoder/security/code-scanning/7

  3. Update versions of some third-party workflows used.

Changes:

1) Add a top-level default permissions declarations to `ci.yml` to
   address https://github.com/quantumlib/tesseract-decoder/security/code-scanning/4

2) Add commit hashes to third-party workflow references that didn't have them

3) Update versions of some third-party workflows used.
@mhucka mhucka requested a review from a team as a code owner November 4, 2025 16:14
@mhucka mhucka requested review from LalehB and removed request for a team November 4, 2025 16:14
@mhucka mhucka added area/health Project health, code health, and similar meta-level concerns area/devops Involves build systems, Make files, Bazel files, continuous integration, and/or other DevOps topics labels Nov 4, 2025
Copy link
Collaborator

@LalehB LalehB left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@mhucka mhucka merged commit e5ec96c into quantumlib:main Nov 10, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/devops Involves build systems, Make files, Bazel files, continuous integration, and/or other DevOps topics area/health Project health, code health, and similar meta-level concerns

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants