diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 6bec909..1e186f6 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,6 +18,9 @@ on: # The branches below must be a subset of the branches above branches: [ "main" ] +permissions: + contents: read + jobs: analyze: if: "!contains(github.event.commits[0].message, '[noci]')" diff --git a/.github/workflows/container.yml b/.github/workflows/container.yml index fe57d2f..bb12c25 100644 --- a/.github/workflows/container.yml +++ b/.github/workflows/container.yml @@ -7,6 +7,9 @@ on: branches: - "main" +permissions: + contents: read + env: REGISTRY: ghcr.io IMAGE_NAME: ${{ github.repository }} diff --git a/.github/workflows/secret_scan.yml b/.github/workflows/secret_scan.yml index 783000d..13b1993 100644 --- a/.github/workflows/secret_scan.yml +++ b/.github/workflows/secret_scan.yml @@ -3,6 +3,10 @@ on: pull_request: branches: - main + +permissions: + contents: read + jobs: trufflehog: runs-on: ubuntu-latest