diff --git a/.github/workflows/trivy-scan.yml b/.github/workflows/trivy-scan.yml index 4951d1af2..5dcf51a5d 100644 --- a/.github/workflows/trivy-scan.yml +++ b/.github/workflows/trivy-scan.yml @@ -11,6 +11,10 @@ jobs: scan: runs-on: ubuntu-latest + # seems needed for github/codeql-action/upload-sarif + permissions: + actions: write + steps: - name: Checkout code uses: actions/checkout@v4