From ddab980993a579fc468781f16b6361b42438355b Mon Sep 17 00:00:00 2001 From: arena-agent Date: Tue, 22 Sep 2026 12:32:58 +0000 Subject: [PATCH] test(ci): move security-events to job-level only (diagnosing residual startup_failure) All estate repos whose codeql passes keep security-events: write at JOB level only (hypatia, nexia-list, standards canonical). vexometer is the sole remaining startup_failure after the v4.38.1 rollback (#90), and its codeql.yml is the only one ALSO granting it at workflow top level. This is a measurement PR: if the pin rollback alone was insufficient, the top-level grant variant is now the only structural difference. --- .github/workflows/codeql.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 8ff6960..b4b8cc7 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -13,7 +13,6 @@ on: permissions: actions: read contents: read - security-events: write jobs: analyze: