From 09052fa91ae9259dae6fb0baea7cb29bbb5cb2fd Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 23 Jul 2026 16:00:47 -0400 Subject: [PATCH] chore: resolve open code scanning alerts (#58) * ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alerts #9 and #11 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match. * fix: turn off debug mode in Flask app configuration. Resolves code scanning alert #2 (Flask app is run in debug mode) * ci: bump reusable workflow pin to f71002a (ruff 0.15.22 pin) Picks up Sea-Haven-Industries/.github#88, which pins ruff in ci-python-sam so unpinned installs no longer float to new releases with changed default rule sets (0.16.0 broke CI with 89 pre-existing findings). Refs Sea-Haven-Industries/.github#87. --- .github/workflows/ci.yml | 5 ++++- .github/workflows/dependency-review.yml | 7 ++++++- src/server/app.py | 2 +- 3 files changed, 11 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6cc6efb..5acb476 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,8 +4,11 @@ on: pull_request: branches: [main] +permissions: + contents: read + jobs: ci: - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@f71002a9ed2938730b683249b28059c92a081af6 # main with: run-tests: true diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2cd8119..b809f8b 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,6 +1,11 @@ name: Dependency Review + on: pull_request: + +permissions: + contents: read + jobs: review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@f71002a9ed2938730b683249b28059c92a081af6 # main diff --git a/src/server/app.py b/src/server/app.py index 40c02d7..c3539b6 100644 --- a/src/server/app.py +++ b/src/server/app.py @@ -374,4 +374,4 @@ if __name__ == "__main__": ORDERS_DIR.mkdir(exist_ok=True) print(f"Menu file: {latest_menu_file()}") print(f"Orders dir: {ORDERS_DIR}") - app.run(host="0.0.0.0", port=5050, debug=True) + app.run(host="0.0.0.0", port=5050, debug=False)