Skip to content
This repository was archived by the owner on Oct 3, 2025. It is now read-only.

Commit 399e19e

Browse files
authored
chore: set explicit workflow permissions (#1143)
1 parent 38f8a70 commit 399e19e

File tree

5 files changed

+20
-3
lines changed

5 files changed

+20
-3
lines changed

.github/workflows/codeql.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,10 @@ on:
2020
schedule:
2121
- cron: '30 4 * * 1'
2222

23+
permissions:
24+
contents: read
25+
packages: read
26+
2327
jobs:
2428
analyze:
2529
name: Analyze

.github/workflows/docker.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,10 @@ name: Docker
33

44
on: workflow_dispatch
55

6+
permissions:
7+
contents: read
8+
packages: write
9+
610
jobs:
711
build:
812
runs-on: ubuntu-latest

.github/workflows/publish.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,10 @@ on:
88
tags:
99
- 'v*'
1010

11+
permissions:
12+
contents: write
13+
packages: read
14+
1115
jobs:
1216
publish:
1317
runs-on: ubuntu-latest

.github/workflows/stale.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,13 @@ on:
33
schedule:
44
- cron: "30 1 * * *"
55

6+
permissions:
7+
issues: write
8+
pull-requests: write
9+
610
jobs:
711
close-issues:
812
runs-on: ubuntu-latest
9-
permissions:
10-
issues: write
11-
pull-requests: write
1213
steps:
1314
- uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639
1415
with:

.github/workflows/verify.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,10 @@ on:
1212
- main
1313
merge_group:
1414

15+
permissions:
16+
contents: read
17+
packages: read
18+
1519
jobs:
1620
node:
1721
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)