Reusable workflow calls inherit only explicitly granted permissions. The nested security job requires packages: read and security-events: write for CodeQL analysis. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reusable workflow calls inherit only explicitly granted permissions. The nested security job requires packages: read and security-events: write for CodeQL analysis. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>