From 393e9c44ae2959d2f6fbf90d23ca18e786d87a4a Mon Sep 17 00:00:00 2001 From: MIA_Ether <2452597472@qq.com> Date: Thu, 1 Oct 2026 15:44:53 +0800 Subject: [PATCH] ci: scope codeql permissions to analysis job Signed-off-by: MIA_Ether <2452597472@qq.com> --- .github/workflows/codeql.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 288b39b962..6b4493785c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,4 @@ -# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. +# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. # SPDX-License-Identifier: Apache-2.0 name: CodeQL @@ -20,7 +20,6 @@ on: permissions: contents: read - security-events: write concurrency: group: codeql-${{ github.workflow }}-${{ inputs.candidate_ref || github.ref }} @@ -30,6 +29,9 @@ jobs: analyze: name: CodeQL (${{ matrix.language }}) runs-on: ubuntu-latest + permissions: + contents: read + security-events: write timeout-minutes: 90 env: # Keep Rust test fixtures out of production-focused security results. @@ -166,3 +168,4 @@ jobs: exit 1 fi echo "All CodeQL analyzers completed and the configured finding threshold passed." +