Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Copilot Autofix
AI 14 days ago
To fix the issue, add an explicit
permissionsblock that grants the least privileges needed for this workflow. Since this workflow simply triggers a reusable workflow onpull_requestevents and does not itself perform any repository modifications, a safe and minimal default is to restrict GITHUB_TOKEN to read-only access to repository contents.The best targeted fix without changing existing functionality is to add a top-level
permissions:section (applies to all jobs) or a job-levelpermissions:underjobs.approve. Both satisfy CodeQL; using a top-level block is clearer and future-proof if additional jobs are added. We’ll add:between the
on:block and thejobs:block in.github/workflows/renovate-approve.yml. This documents that the workflow only needs read access to repository contents and ensures the token is not granted unnecessary write privileges. No imports or additional definitions are required.