diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml index dbb49cca95..57a6e255e8 100644 --- a/.github/workflows/scan.yml +++ b/.github/workflows/scan.yml @@ -16,6 +16,11 @@ concurrency: group: scan-${{ github.ref }} cancel-in-progress: true +permissions: + contents: read + packages: read + security-events: write + jobs: analyze: name: Analyze