diff --git a/.github/workflows/build-docs.yml b/.github/workflows/build-docs.yml index d05ffaa2..c20fcb14 100644 --- a/.github/workflows/build-docs.yml +++ b/.github/workflows/build-docs.yml @@ -9,6 +9,9 @@ on: paths: - 'docs**/' - '.github/workflows/build-docs.yml' +permissions: + contents: read + jobs: build-documentation: name: docs diff --git a/.github/workflows/build-gluon.yml b/.github/workflows/build-gluon.yml index 141d6d83..561ff0cc 100644 --- a/.github/workflows/build-gluon.yml +++ b/.github/workflows/build-gluon.yml @@ -8,8 +8,14 @@ on: pull_request: types: [opened, synchronize, reopened] +permissions: + contents: read + jobs: changed: + permissions: + contents: read # for dorny/paths-filter to fetch a list of changed files + pull-requests: read # for dorny/paths-filter to read pull requests runs-on: ubuntu-latest outputs: targets: ${{ steps.filter.outputs.changes }} diff --git a/.github/workflows/check-patches.yml b/.github/workflows/check-patches.yml index ba46d407..303ef7ac 100644 --- a/.github/workflows/check-patches.yml +++ b/.github/workflows/check-patches.yml @@ -12,6 +12,9 @@ on: - 'modules' - 'patches/**' - '.github/workflows/check-patches.yml' +permissions: + contents: read + jobs: check-patches: name: Check patches diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index 67f9302d..edd88a25 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -4,8 +4,14 @@ on: # only execute base branch actions pull_request_target: +permissions: + contents: read + jobs: labels: + permissions: + contents: read # for actions/labeler to determine modified files + pull-requests: write # for actions/labeler to add labels to PRs runs-on: ubuntu-latest if: github.repository_owner == 'freifunk-gluon' steps: diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 8acba44a..ce830eff 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -3,6 +3,9 @@ on: push: pull_request: types: [opened, synchronize, reopened] +permissions: + contents: read + jobs: lua: name: Lua