We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent bf91b40 commit e2753b7Copy full SHA for e2753b7
.github/workflows/osv.yml
@@ -15,13 +15,11 @@ on:
15
branches: [main]
16
17
permissions:
18
- # Required to upload SARIF file to CodeQL. See: https://github.com/github/codeql-action/issues/2117
19
actions: read
20
- # Require writing security events to upload SARIF file to security tab
21
- security-events: write
22
- # Only need to read contents
23
contents: read
24
25
jobs:
26
scan-pr:
+ permissions:
+ security-events: write
27
uses: "google/osv-scanner-action/.github/workflows/[email protected]"
0 commit comments