Skip to content

Commit 66d6b38

Browse files
committed
ci: add default read-only permissions
1 parent 21a4b80 commit 66d6b38

2 files changed

Lines changed: 10 additions & 0 deletions

File tree

.github/workflows/main.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ on:
66
- main
77
- beta
88

9+
permissions:
10+
contents: read
11+
912
jobs:
1013
Install:
1114
runs-on: ubuntu-latest
@@ -104,6 +107,10 @@ jobs:
104107
Release:
105108
# Prevent infinite release loop
106109
if: ${{ !startsWith(github.event.head_commit.message, 'chore(release)') }}
110+
permissions:
111+
contents: write
112+
issues: write
113+
pull_requests: write
107114
needs:
108115
- Lint
109116
- Typecheck

.github/workflows/release.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ on:
88
# Beta release tags, e.g. "v3.0.0-beta.1"
99
- 'v[0-9]+.[0-9]+.[0-9]+-beta.[0-9]+'
1010

11+
permissions:
12+
contents: read
13+
1114
jobs:
1215
Install:
1316
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)