From d270bc1870b20c33757bdf908fc1fd6c7a7486dd Mon Sep 17 00:00:00 2001 From: Nat Dean-Lewis <94526761+natdeanlewissoftwire@users.noreply.github.com> Date: Thu, 4 Jun 2026 16:23:47 +0100 Subject: [PATCH] Potential fix for pull request finding 'CodeQL / Workflow does not contain permissions' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/upload-sbom.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/upload-sbom.yml b/.github/workflows/upload-sbom.yml index 1bd1c09d8..f1c02a0ec 100644 --- a/.github/workflows/upload-sbom.yml +++ b/.github/workflows/upload-sbom.yml @@ -15,6 +15,9 @@ on: DTRACK_API_KEY: required: true +permissions: + contents: read + jobs: sbom: name: Generate and upload SBOM