From fcf0a87b5fc49c5f793668ebc11d2a06050351cf Mon Sep 17 00:00:00 2001 From: "(skovati) Luke" Date: Mon, 14 Oct 2024 15:15:20 -0700 Subject: [PATCH] add `GITHUB_TOKEN` to security scan build environment --- .github/workflows/security-scan.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index f2034d59d1..06c05221cf 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -12,6 +12,9 @@ on: - v* workflow_dispatch: +env: + GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}" + jobs: analyze: name: Analyze @@ -19,6 +22,7 @@ jobs: permissions: actions: read contents: write + packages: read security-events: write strategy: