diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 1f51c2e..728ee9d 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -13,11 +13,15 @@ on: workflow_dispatch: # Allow workflow to be triggered manually. +permissions: {} + jobs: detect-secrets: if: "!contains(github.event.head_commit.message, '[skip ci]')" name: detect-secrets runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Checkout repository @@ -42,6 +46,8 @@ jobs: needs: detect-secrets runs-on: ubuntu-latest + permissions: + contents: read strategy: matrix: python-version: ['3.10', '3.11', '3.12', '3.13', '3.14'] @@ -63,6 +69,7 @@ jobs: runs-on: ubuntu-latest name: Final Test Results needs: [build] + permissions: {} steps: - run: | result="${{ needs.build.result }}" @@ -77,6 +84,8 @@ jobs: if: "github.ref_name == 'main' && github.event_name != 'pull_request'" needs: build runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Checkout repository diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 9e2ddff..c4d15f4 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -9,10 +9,14 @@ on: workflow_dispatch: # Allow this workflow to be triggered manually +permissions: {} + jobs: publish: name: publish-release runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Checkout repository