You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Restore a clear permissions example for advanced setup workflows,
including private-repo needs, so existing users can apply the minimum
set without digging through starter templates. Fixes#1913.
Copy file name to clipboardExpand all lines: README.md
+20-1Lines changed: 20 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -38,7 +38,26 @@ Actions with special purposes and unlikely to be used directly:
38
38
39
39
### Workflow Permissions
40
40
41
-
All advanced setup code scanning workflows must have the `security-events: write` permission. Workflows in private repositories must additionally have the `contents: read` permission. For more information, see "[Assigning permissions to jobs](https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs)."
41
+
All advanced setup code scanning workflows need certain permissions. At minimum:
42
+
43
+
```yaml
44
+
permissions:
45
+
# required for all workflows
46
+
security-events: write
47
+
48
+
# required to fetch internal or private CodeQL packs
49
+
packages: read
50
+
51
+
# only required for workflows in private repositories
52
+
actions: read
53
+
contents: read
54
+
```
55
+
56
+
- `security-events: write` is required so the action can upload results to code scanning.
57
+
- `packages: read` is needed when the workflow fetches internal or private CodeQL packs.
58
+
- `actions: read` and `contents: read` are required for workflows in private repositories.
59
+
60
+
For more information, see "[Assigning permissions to jobs](https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs)" and the [CodeQL starter workflow](https://github.com/actions/starter-workflows/blob/main/code-scanning/codeql.yml).
0 commit comments