Skip to content

Add vulnerability-alerts permission to workflow schema#356

Draft
salmanmkc wants to merge 1 commit intomainfrom
vulnerability-alerts-permission
Draft

Add vulnerability-alerts permission to workflow schema#356
salmanmkc wants to merge 1 commit intomainfrom
vulnerability-alerts-permission

Conversation

@salmanmkc
Copy link
Copy Markdown
Contributor

@salmanmkc salmanmkc commented Apr 15, 2026

Summary

Add vulnerability-alerts as a new read-only permission key in the workflow schema permissions-mapping.

Changes

  • Added vulnerability-alerts with permission-level-read-or-no-access type (only read and none are valid)
  • Updated security-events description to Code scanning alerts. (Dependabot alerts now have their own key)

Add vulnerability-alerts as a new read-only permission key in the
permissions-mapping. This permission allows workflows to read
Dependabot alerts via GITHUB_TOKEN.

Uses permission-level-read-or-no-access type (read and none only).
Updated security-events description to reflect it covers code
scanning alerts only.
@salmanmkc
Copy link
Copy Markdown
Contributor Author

Related PRs

Part of the vulnerability-alerts permission rollout. Independent change — no blocking dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant