diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 80e0e62..07073b7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -140,6 +140,10 @@ jobs: security-scan: name: Security Scan runs-on: ubuntu-latest + permissions: + contents: read + security-events: write + actions: read steps: - uses: actions/checkout@v4 @@ -155,7 +159,7 @@ jobs: output: 'trivy-results.sarif' - name: Upload Trivy results to GitHub Security - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 if: always() with: sarif_file: 'trivy-results.sarif'