From 7f34718d4f84932ae8719f6d196bc19736c573e2 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:33:17 -0400 Subject: [PATCH 1/2] ci: scope down permissions for pr.yml --- .github/workflows/pr.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index e469085a0..1b2c3981b 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -5,6 +5,9 @@ on: branches: - main +permissions: + contents: read + jobs: build: name: Build on ${{ matrix.os }} From a374849c53b3876c749e105a6c21e4394c2e3f92 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Tue, 21 Oct 2025 14:33:19 -0400 Subject: [PATCH 2/2] ci: scope down permissions for main.yml --- .github/workflows/main.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index fcb666e0d..6f46b329f 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -9,6 +9,9 @@ on: - main +permissions: + contents: write + jobs: publish-smoke-test: runs-on: ubuntu-22.04