ci(codeql): explicitly grant runner token permissions

This allows us to make our runner token only have read-only permissions
by default

Signed-off-by: Seth Flynn <getchoo@tuta.io>
This commit is contained in:
Seth Flynn 2026-02-02 16:51:58 -05:00
parent f85e2ddb15
commit e0ad6a2b3b
No known key found for this signature in database
GPG key ID: D31BD0D494BBEE86

View file

@ -58,10 +58,16 @@ on:
- ".github/actions/setup-dependencies/**"
workflow_dispatch:
permissions: {}
jobs:
CodeQL:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v6