Skip to content

Fix CodeQL with Dependabot #3316

Closed
@andyleejordan

Description

@andyleejordan

Now that Dependabot is opening PRs again (per #3310), I can't seem to merge them because CodeQL fails with this error:

Error: Workflows triggered by Dependabot on the "push" event run with read-only access. Uploading Code Scanning results requires write access. To use Code Scanning with Dependabot, please ensure you are using the "pull_request" event for this workflow and avoid triggering on the "push" event for Dependabot branches. See https://docs.github.com/en/code-security/secure-coding/configuring-code-scanning#scanning-on-push for more information on how to configure these events.

See #3313 for an example.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions