소스 검색

fix: adding required permissions to top level and jobs in the workflow (#3740)

Signed-off-by: Gagan H R <hrgagan4@gmail.com>
Gagan H R 3 주 전
부모
커밋
a58a7cbbd9
1개의 변경된 파일5개의 추가작업 그리고 4개의 파일을 삭제
  1. 5 4
      .github/workflows/vulnerability-scan.yaml

+ 5 - 4
.github/workflows/vulnerability-scan.yaml

@@ -1,9 +1,6 @@
 name: Trivy Vulnerability Scanner
 
-permissions:
-  issues: write
-  contents: read
-  security-events: write
+permissions: {}
 
 on:
   pull_request:
@@ -19,6 +16,10 @@ jobs:
   scan:
     name: Scan for Vulnerabilities
     runs-on: ubuntu-latest
+    permissions:
+      issues: write
+      contents: read
+      security-events: write
     steps:
       - name: Checkout code
         uses: actions/checkout@v6.0.2