From dcd19e9e952fd0e90ac42e139dfa3be16f89dd31 Mon Sep 17 00:00:00 2001 From: dongjiang Date: Mon, 15 Jun 2026 13:29:13 +0800 Subject: [PATCH] Potential fix for code scanning alert no. 18: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Signed-off-by: dongjiang --- .github/workflows/security.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index ba9189e..d894617 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -6,6 +6,9 @@ on: pull_request: branches: [main] +permissions: + contents: read + jobs: audit: name: Dependency Audit