aboutsummaryrefslogtreecommitdiff
path: root/.github
diff options
context:
space:
mode:
authorJoe Chen <jc@unknwon.io>2021-12-18 01:03:01 +0800
committerGitHub <noreply@github.com>2021-12-18 01:03:01 +0800
commitf1f3e970b97ee089b6532d6aa4b68551b4165169 (patch)
tree909a8be8c3a1809290618412d80a77a7452451e2 /.github
parentb827a2f3428e24ce77ec48e824844299e185e539 (diff)
github: fix CodeQL token permissions (#6676)
Diffstat (limited to '.github')
-rw-r--r--.github/workflows/codeql.yml9
1 files changed, 4 insertions, 5 deletions
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 065821e7..6bd2d0e5 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -20,6 +20,10 @@ on:
schedule:
- cron: '0 19 * * 0'
+permissions:
+ contents: read
+ security-events: write
+
jobs:
analyze:
name: Analyze
@@ -41,11 +45,6 @@ jobs:
# a pull request then we can checkout the head.
fetch-depth: 2
- # If this run was triggered by a pull request event, then checkout
- # the head of the pull request instead of the merge commit.
- - run: git checkout HEAD^2
- if: ${{ github.event_name == 'pull_request' }}
-
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1