chore: resolve open code scanning alerts (#58)
Some checks failed
Deploy / deploy (push) Has been cancelled

* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alerts #9 and #11 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.

* fix: turn off debug mode in Flask app configuration.

Resolves code scanning alert #2 (Flask app is run in debug mode)

* ci: bump reusable workflow pin to f71002a (ruff 0.15.22 pin)

Picks up Sea-Haven-Industries/.github#88, which pins ruff in
ci-python-sam so unpinned installs no longer float to new releases
with changed default rule sets (0.16.0 broke CI with 89 pre-existing
findings). Refs Sea-Haven-Industries/.github#87.
This commit is contained in:
Adam Moussa 2026-07-23 16:00:47 -04:00 • committed by GitHub
parent 4079d57757
commit 09052fa91a
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 11 additions and 3 deletions

View file

@ -4,8 +4,11 @@ on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@f71002a9ed2938730b683249b28059c92a081af6 # main
with:
run-tests: true

View file

@ -1,6 +1,11 @@
name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@f71002a9ed2938730b683249b28059c92a081af6 # main

View file

@ -374,4 +374,4 @@ if __name__ == "__main__":
ORDERS_DIR.mkdir(exist_ok=True)
print(f"Menu file: {latest_menu_file()}")
print(f"Orders dir: {ORDERS_DIR}")
app.run(host="0.0.0.0", port=5050, debug=True)
app.run(host="0.0.0.0", port=5050, debug=False)