diff --git a/.github/workflows/vulncheck.yml b/.github/workflows/vulncheck.yml index db6a8b292..a65c768b0 100644 --- a/.github/workflows/vulncheck.yml +++ b/.github/workflows/vulncheck.yml @@ -6,6 +6,10 @@ on: push: branches: - master + +permissions: + contents: read # to fetch code (actions/checkout) + jobs: vulncheck: name: Analysis