diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 073c073c5508..debe26a5b146 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -7,6 +7,9 @@ on: env: GOPATH: ${{ github.workspace }}/go +permissions: + contents: read + jobs: test-and-verify: runs-on: ubuntu-latest diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index 3fca2de3323a..c201c47f5a2b 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -1,5 +1,11 @@ +permissions: + contents: read + jobs: changes: + permissions: + contents: read # for dorny/paths-filter to fetch a list of changed files + pull-requests: read # for dorny/paths-filter to read pull requests outputs: charts: ${{ steps.filter.outputs.charts }} runs-on: ubuntu-latest diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 15fa1c251978..4b7ff78a43af 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -1,5 +1,10 @@ +permissions: + contents: read + jobs: release: + permissions: + contents: write # for helm/chart-releaser-action to push chart release and create a release runs-on: ubuntu-latest steps: - name: Checkout