From 9b7081a834b01bef23e73299521cb0981dba0fe2 Mon Sep 17 00:00:00 2001 From: enrico-kaack-comp Date: Thu, 20 Mar 2025 13:59:56 +0100 Subject: [PATCH] add minimal permission on gh action --- .github/workflows/build.yaml | 3 ++- .github/workflows/on-pr.yaml | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index b3ff9da7..d88fd9d2 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -6,7 +6,8 @@ on: jobs: build: runs-on: ubuntu-latest - + permissions: + contents: read steps: - name: Checkout code uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 diff --git a/.github/workflows/on-pr.yaml b/.github/workflows/on-pr.yaml index 77fb1775..cd95a673 100644 --- a/.github/workflows/on-pr.yaml +++ b/.github/workflows/on-pr.yaml @@ -1,5 +1,6 @@ name: On Pull Request - +permissions: + contents: read on: pull_request: types: