anchore / grype

A vulnerability scanner for container images and filesystems
Apache License 2.0
8.19k stars 529 forks source link

chore: add top level permissions to new workflow #1860

Closed spiffcs closed 1 month ago

spiffcs commented 1 month ago

Summary

Best practices for github workflows detail that top level permissions should be declarative read.

This PR updates the top level permissions for the release-version-file to contents:read