From 946965f0165cbbcf655bbed20931d51c5bff012a Mon Sep 17 00:00:00 2001 From: Kevin Veen-Birkenbach Date: Thu, 26 Mar 2026 16:33:40 +0100 Subject: [PATCH] fix(ci): grant reusable workflows security permissions --- .github/workflows/ci.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a5ffea4..e43ccad 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,6 +12,10 @@ concurrency: jobs: security-codeql: + permissions: + contents: read + packages: read + security-events: write uses: ./.github/workflows/security-codeql.yml test-unit: @@ -42,4 +46,7 @@ jobs: uses: ./.github/workflows/lint-python.yml lint-docker: + permissions: + contents: read + security-events: write uses: ./.github/workflows/lint-docker.yml