From b0a67c022ffe0f6e6711b35f7a52129145fd7334 Mon Sep 17 00:00:00 2001 From: Matt Collins Date: Wed, 10 Jun 2026 05:30:24 +0000 Subject: [PATCH 1/2] chore: upgrade IABTechLab/uid2-shared-actions from v2 to v3 --- .github/workflows/check-stable-dependency.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/check-stable-dependency.yaml b/.github/workflows/check-stable-dependency.yaml index f8a417b55..38aea7689 100644 --- a/.github/workflows/check-stable-dependency.yaml +++ b/.github/workflows/check-stable-dependency.yaml @@ -3,5 +3,5 @@ on: [pull_request, workflow_dispatch] jobs: check_dependency: - uses: IABTechLab/uid2-shared-actions/.github/workflows/shared-check-stable-dependency.yaml@v2 + uses: IABTechLab/uid2-shared-actions/.github/workflows/shared-check-stable-dependency.yaml@v3 secrets: inherit \ No newline at end of file From 5291248446d88c13e5a924a158b70226dd0faad2 Mon Sep 17 00:00:00 2001 From: mcollins-ttd <118872455+mcollins-ttd@users.noreply.github.com> Date: Wed, 10 Jun 2026 06:10:30 +0000 Subject: [PATCH 2/2] fix: add minimal GITHUB_TOKEN permissions to address CodeQL warning --- .github/workflows/check-stable-dependency.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/check-stable-dependency.yaml b/.github/workflows/check-stable-dependency.yaml index 38aea7689..cbcd4664f 100644 --- a/.github/workflows/check-stable-dependency.yaml +++ b/.github/workflows/check-stable-dependency.yaml @@ -1,7 +1,10 @@ name: Check Stable Dependencies on: [pull_request, workflow_dispatch] +permissions: + contents: read + jobs: check_dependency: uses: IABTechLab/uid2-shared-actions/.github/workflows/shared-check-stable-dependency.yaml@v3 - secrets: inherit \ No newline at end of file + secrets: inherit