From ba5f44d4f9b84c20ae7b7d9c18a2883ae5e9a2a7 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:46:30 -0400 Subject: [PATCH 1/3] ci: scope down permissions for ci.yaml --- .github/workflows/ci.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 3e476ffe..39e1574d 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -6,6 +6,9 @@ on: pull_request: branches: [ main ] +permissions: + contents: read + jobs: build: runs-on: macos-15 From 1c67c0d784b338141504077109fb422b5a411191 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:46:32 -0400 Subject: [PATCH 2/3] ci: scope down permissions for e2e.yaml --- .github/workflows/e2e.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/e2e.yaml b/.github/workflows/e2e.yaml index faf5708f..7ef837bf 100644 --- a/.github/workflows/e2e.yaml +++ b/.github/workflows/e2e.yaml @@ -2,6 +2,9 @@ name: "E2E Pipeline for CDK Observability Accelerator" on: issue_comment: types: [created] +permissions: + statuses: write + jobs: checkPermissions: runs-on: ubuntu-latest From 1e6cfd3ee8d2704298d2fbf93a50f1961e498db6 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:46:34 -0400 Subject: [PATCH 3/3] ci: scope down permissions for markdown-link-check.yaml --- .github/workflows/markdown-link-check.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/markdown-link-check.yaml b/.github/workflows/markdown-link-check.yaml index 7d2a2f19..73797673 100644 --- a/.github/workflows/markdown-link-check.yaml +++ b/.github/workflows/markdown-link-check.yaml @@ -13,6 +13,9 @@ on: paths: - "**/*.md" +permissions: + contents: read + jobs: markdown-link-check: runs-on: ubuntu-latest