Skip to content

Commit 09def6f

Browse files
CCM-15866: Address Even More Sonar Findings (#107)
1 parent 4831740 commit 09def6f

3 files changed

Lines changed: 5 additions & 5 deletions

File tree

.github/workflows/scorecard.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,9 @@ on:
1414
push:
1515
branches: [ "main" ]
1616

17-
# Declare default permissions as read only.
18-
permissions: read-all
17+
# Declare default permissions explicitly as read-only.
18+
permissions:
19+
contents: read
1920

2021
jobs:
2122
analysis:

.github/workflows/stage-2-test.yaml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,8 +37,7 @@ env:
3737
TERM: xterm-256color
3838

3939
permissions:
40-
id-token: write # This is required for requesting the JWT
41-
contents: read # This is required for actions/checkout
40+
contents: read # This is required for actions/checkout
4241

4342
jobs:
4443
check-generated-dependencies:

scripts/config/sonar-scanner.properties

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ sonar.host.url=https://sonarcloud.io
44
sonar.qualitygate.wait=true
55
sonar.sourceEncoding=UTF-8
66
sonar.sources=.
7-
sonar.exclusions=lambdas/*/src/__tests__/**/*,containers/**/src/__tests__,infrastructure/terraform/bin/terraform.sh
7+
sonar.exclusions=lambdas/*/src/__tests__/**/*,containers/**/src/__tests__/**/*,infrastructure/terraform/bin/terraform.sh
88
sonar.terraform.provider.aws.version=5.54.1
99
sonar.cpd.exclusions=**.test.*
1010
sonar.coverage.exclusions=tests/, **/*.dev.*, lambdas/**/src/__tests__, utils/utils/src/zod-validators.ts ,**/jest.config.ts,scripts/**/*, containers/**/src/__tests__, eslint.config.mjs, docs/assets/js/nhs-notify.js, containers/example-app/src/server.ts

0 commit comments

Comments
 (0)