Ensure correct CodeQL workflow permissions #19
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR adds the required
security-events: write
permission at the job level for the CodeQL workflow that runsgithub/codeql-action/analyze
.Changes Made
permissions: security-events: write
to theCodeQL-Build
job in.github/workflows/codeql-analysis.yml
Background
GitHub Actions workflows that use
github/codeql-action/analyze
require thesecurity-events: write
permission to upload code scanning results. This permission should be defined at the job level rather than the workflow root level to follow the principle of least privilege.Verification
github/codeql-action/analyze
Fixes #18.
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.