Skip to content

Commit d390659

Browse files
committed
Add missing permissions
1 parent 1645dbd commit d390659

13 files changed

+53
-1
lines changed

.github/workflows/check-expected-release-files.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,9 @@ jobs:
1313
check-expected-release-files:
1414
runs-on: ubuntu-latest
1515

16+
permissions:
17+
contents: read
18+
1619
steps:
1720
- name: Checkout CodeQL Action
1821
uses: actions/checkout@v4

.github/workflows/codescanning-config-cli.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,11 @@ jobs:
2323
code-scanning-config-tests:
2424
continue-on-error: true
2525

26+
permissions:
27+
contents: read
28+
packages: read
29+
security-events: write
30+
2631
strategy:
2732
fail-fast: false
2833
matrix:

.github/workflows/debug-artifacts-failure.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ jobs:
2323
continue-on-error: true
2424
env:
2525
CODEQL_ACTION_TEST_MODE: true
26+
permissions:
27+
contents: read
2628
timeout-minutes: 45
2729
runs-on: ubuntu-latest
2830
steps:
@@ -58,6 +60,8 @@ jobs:
5860
name: Download and check debug artifacts after failure in analyze
5961
needs: upload-artifacts
6062
timeout-minutes: 45
63+
permissions:
64+
contents: read
6165
runs-on: ubuntu-latest
6266
steps:
6367
- name: Download all artifacts

.github/workflows/debug-artifacts.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,8 @@ jobs:
3434
env:
3535
CODEQL_ACTION_TEST_MODE: true
3636
timeout-minutes: 45
37+
permissions:
38+
contents: read
3739
runs-on: ubuntu-latest
3840
steps:
3941
- name: Check out repository
@@ -64,6 +66,8 @@ jobs:
6466
name: Download and check debug artifacts
6567
needs: upload-artifacts
6668
timeout-minutes: 45
69+
permissions:
70+
contents: read
6771
runs-on: ubuntu-latest
6872
steps:
6973
- name: Download all artifacts

.github/workflows/post-release-mergeback.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,9 @@ jobs:
2727
BASE_BRANCH: "${{ github.event.inputs.baseBranch || 'main' }}"
2828
HEAD_BRANCH: "${{ github.head_ref || github.ref }}"
2929

30+
permissions:
31+
contents: write # needed to create tags and push commits
32+
3033
steps:
3134
- name: Dump environment
3235
run: env

.github/workflows/pr-checks.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,8 @@ jobs:
4040
check-node-modules:
4141
if: github.event_name != 'push' || github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/heads/releases/v')
4242
name: Check modules up to date
43+
permissions:
44+
contents: read
4345
runs-on: macos-latest
4446
timeout-minutes: 45
4547

@@ -51,6 +53,8 @@ jobs:
5153
check-file-contents:
5254
if: github.event_name != 'push' || github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/heads/releases/v')
5355
name: Check file contents
56+
permissions:
57+
contents: read
5458
runs-on: ubuntu-latest
5559
timeout-minutes: 45
5660

@@ -81,6 +85,8 @@ jobs:
8185
fail-fast: false
8286
matrix:
8387
os: [ubuntu-latest, macos-latest, windows-latest]
88+
permissions:
89+
contents: read
8490
runs-on: ${{ matrix.os }}
8591
timeout-minutes: 45
8692

@@ -101,6 +107,9 @@ jobs:
101107
env:
102108
BASE_REF: ${{ github.base_ref }}
103109

110+
permissions:
111+
contents: read
112+
104113
steps:
105114
- uses: actions/checkout@v4
106115
- id: head-version

.github/workflows/python312-windows.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,8 @@ jobs:
1717
env:
1818
CODEQL_ACTION_TEST_MODE: true
1919
timeout-minutes: 45
20+
permissions:
21+
contents: read
2022
runs-on: windows-latest
2123

2224
steps:

.github/workflows/query-filters.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,8 @@ jobs:
1919
query-filters:
2020
name: Query Filters Tests
2121
timeout-minutes: 45
22+
permissions:
23+
contents: read
2224
runs-on: ubuntu-latest
2325
steps:
2426
- name: Check out repository

.github/workflows/rebuild.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,9 @@ jobs:
1111
runs-on: ubuntu-latest
1212
if: github.event.label.name == 'Rebuild'
1313

14+
permissions:
15+
contents: write # needed to push rebuilt commit
16+
pull-requests: write # needed to comment on the PR
1417
steps:
1518
- name: Checkout
1619
uses: actions/checkout@v4

.github/workflows/update-bundle.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,9 @@ jobs:
1717
update-bundle:
1818
if: github.event.release.prerelease && startsWith(github.event.release.tag_name, 'codeql-bundle-')
1919
runs-on: ubuntu-latest
20+
permissions:
21+
contents: write # needed to push commits
22+
pull-requests: write # needed to create pull requests
2023
steps:
2124
- name: Dump environment
2225
run: env

0 commit comments

Comments
 (0)