From ae46ea4bd325c3ba23686a8aa53e65f56bf6ffb9 Mon Sep 17 00:00:00 2001 From: majinghe <42570491+majinghe@users.noreply.github.com> Date: Wed, 10 Dec 2025 12:07:28 +0800 Subject: [PATCH] fix github action security found by github CodeQL (#1091) --- .github/workflows/helm-package.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/helm-package.yml b/.github/workflows/helm-package.yml index 9c7b46ee..ccefc6eb 100644 --- a/.github/workflows/helm-package.yml +++ b/.github/workflows/helm-package.yml @@ -5,6 +5,9 @@ on: workflows: ["Build and Release"] types: [completed] +permissions: + contents: read + env: new_version: ${{ github.event.workflow_run.head_branch }}