Skip to content

Update .github/workflows/dtrack-sbom.workflow.yaml

76654ad
Select commit
Loading
Failed to load commit list.
Merged

feat: publish sbom to dtrack #767

Update .github/workflows/dtrack-sbom.workflow.yaml
76654ad
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Dec 16, 2025 in 3s

1 new alert including 1 medium severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 45 in .github/workflows/dtrack-sbom.workflow.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}