Kaynağa Gözat

Explicit Permissions for codeql.yml

Rob Winch 2 ay önce
ebeveyn
işleme
2c5bd4c916
1 değiştirilmiş dosya ile 5 ekleme ve 1 silme
  1. 5 1
      .github/workflows/codeql.yml

+ 5 - 1
.github/workflows/codeql.yml

@@ -7,7 +7,11 @@ on:
   schedule:
     # https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule
     - cron: '0 5 * * *'
-
+permissions: read-all
 jobs:
   codeql-analysis-call:
+    permissions:
+      actions: read
+      contents: read
+      security-events: write
     uses: spring-io/github-actions/.github/workflows/codeql-analysis.yml@1