generated from home-assistant/addons-example
-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
ci-cdCI/CD & release pipelineCI/CD & release pipelineinfoNice to have improvementNice to have improvement
Description
Description
The `build_and_publish` job declares `security-events: write` permission but no SARIF upload or security scanning step exists in the workflow.
File(s)
- `.github/workflows/release.yml` (line 81)
Evidence
```yaml
permissions:
contents: read
packages: write
security-events: write # Unused
```
The scan build loads an image but never runs a scanner.
Recommendation
Either:
- Remove the unused permission (principle of least privilege), OR
- Add a Trivy or Grype scanning step after the scan build
Risk if Ignored
Unused permissions create a false sense of security scanning. Minor security debt.
Found by: CI/CD & Release Pipeline Specialist (Agent 3) | Reviewed by: Critique Agent
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
ci-cdCI/CD & release pipelineCI/CD & release pipelineinfoNice to have improvementNice to have improvement