From aa2f52bdcc5a24fc569b935d112a55634eb041c4 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Thu, 11 Dec 2025 18:11:28 -0500 Subject: [PATCH] ci: scope down permissions for codeql-analysis.yml --- .github/workflows/codeql-analysis.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 8ca6194..574b60b 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -20,6 +20,9 @@ on: schedule: - cron: '41 15 * * 0' +permissions: + security-events: write + jobs: analyze: name: Analyze