Add security-events: write permission to CodeQL workflow job #15
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The CodeQL Analysis workflow was missing the required
security-events: write
permission needed for uploading security scanning results to GitHub's code scanning dashboard.Changes Made
permissions:
section withsecurity-events: write
to theCodeQL-Build
job in.github/workflows/codeql-analysis.yml
Why This Change Was Needed
Jobs that use
github/codeql-action/analyze
require thesecurity-events: write
permission to successfully upload analysis results. Without this permission, the CodeQL action may fail to publish security findings to the repository's security dashboard.Validation
github/codeql-action/analyze
Fixes #14.
💬 Share your feedback on Copilot coding agent for the chance to win a $200 gift card! Click here to start the survey.