diff --git a/.github/workflows/notify_release.yml b/.github/workflows/notify_release.yml index 08daed1090..024afbc2b1 100644 --- a/.github/workflows/notify_release.yml +++ b/.github/workflows/notify_release.yml @@ -9,6 +9,9 @@ on: types: [created, released] # A workflow run is made up of one or more jobs that can run sequentially or in parallel +permissions: + contents: read + jobs: # This workflow contains a single job called "notify" notify: diff --git a/.github/workflows/release_pr.yml b/.github/workflows/release_pr.yml index 0698d20140..b1960c663e 100644 --- a/.github/workflows/release_pr.yml +++ b/.github/workflows/release_pr.yml @@ -5,6 +5,10 @@ env: GIT_USER_NAME: awsmobilesdk-dev+ghops GIT_USER_EMAIL: awsmobilesdk-dev+ghops@amazon.com BASE_BRANCH: main +permissions: + contents: write + pull-requests: write + jobs: create_pr_for_next_release: runs-on: ubuntu-latest