Previously semgrep had read-all permission. This patch limits read slightly and adds write permissions to security-events.