Skip to content

Commit c3ed1a9

Browse files
fix(ci): add required permissions for reusable workflows (Bug B)
Add security-events: write and id-token: write to workflow-level permissions in scorecard.yml for scorecard-reusable.yml calls. Ensure contents: read at workflow-level for secret-scanner.yml. Part of hyperpolymath/standards#426 remediation - Batch 2. Generated by Mistral Vibe. Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
1 parent 2ba5c24 commit c3ed1a9

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

‎.github/workflows/scorecard.yml‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,10 @@ on:
88
push:
99
branches: [main]
1010

11-
permissions: read-all
11+
permissions:
12+
contents: read
13+
security-events: write
14+
id-token: write
1215

1316
jobs:
1417
analysis:

0 commit comments

Comments
 (0)