Skip to content

Commit be5385c

Browse files
committed
ci: set permissions for nested workflows
1 parent 938092e commit be5385c

File tree

1 file changed

+12
-2
lines changed

1 file changed

+12
-2
lines changed

.github/workflows/test-changes.yml

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -204,9 +204,19 @@ jobs:
204204
205205
call-workflow-codeql:
206206
needs: test-source-code
207-
uses: ./.github/workflows/codeql-analysis.yml@master
207+
uses: ./.github/workflows/codeql-analysis.yml
208+
permissions:
209+
actions: read
210+
contents: read
211+
pull-requests: write
212+
security-events: write
208213

209214
call-workflow-codacity:
210215
needs: test-source-code
211-
uses: ./.github/workflows/codacy-analysis.yml@master
216+
uses: ./.github/workflows/codacy-analysis.yml
217+
permissions:
218+
actions: read
219+
contents: read
220+
pull-requests: write
221+
security-events: write
212222

0 commit comments

Comments
 (0)