From 802804188f721d9f84de9f6ebf302f397f38693c Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:51:20 -0400 Subject: [PATCH 1/2] ci: scope down permissions for release_pr.yml --- .github/workflows/release_pr.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/release_pr.yml b/.github/workflows/release_pr.yml index 0698d20140..b1960c663e 100644 --- a/.github/workflows/release_pr.yml +++ b/.github/workflows/release_pr.yml @@ -5,6 +5,10 @@ env: GIT_USER_NAME: awsmobilesdk-dev+ghops GIT_USER_EMAIL: awsmobilesdk-dev+ghops@amazon.com BASE_BRANCH: main +permissions: + contents: write + pull-requests: write + jobs: create_pr_for_next_release: runs-on: ubuntu-latest From 3f39b618ad6a5380691629d28ef7c267a0558f8f Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:51:22 -0400 Subject: [PATCH 2/2] ci: scope down permissions for notify_release.yml --- .github/workflows/notify_release.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/notify_release.yml b/.github/workflows/notify_release.yml index 08daed1090..024afbc2b1 100644 --- a/.github/workflows/notify_release.yml +++ b/.github/workflows/notify_release.yml @@ -9,6 +9,9 @@ on: types: [created, released] # A workflow run is made up of one or more jobs that can run sequentially or in parallel +permissions: + contents: read + jobs: # This workflow contains a single job called "notify" notify: