comparison .github/workflows/anchore.yml @ 7129:c7e35b96907d

Try another permission setup. security events has to be write to allow codeql to work. OSSF-security scan complains with the write at the top level. So leave top level read only and add write at job level. See if codeql will not fail (missing write perms caused failure in codeql init). Note that ossf recommended remediation step using: https://app.stepsecurity.io/secureworkflow/roundup-tracker/roundup/codeql-analysis.yml/master?enable=permissions had no issue with the permissions defined in the workflow. I had a green checkmark.
author John Rouillard <rouilj@ieee.org>
date Mon, 23 Jan 2023 21:21:38 -0500
parents 86dae713d4c6
children 572d1a9f875c
comparison
equal deleted inserted replaced
7128:2685dd56806a 7129:c7e35b96907d

Roundup Issue Tracker: http://roundup-tracker.org/