chore(ci): restrict token permissions (#7470)

Replace read-all with contents:read and add explicit permissions to
follow principle of least privilege.

Signed-off-by: Ville Vesilehto <ville@vesilehto.fi>
This commit is contained in:
Ville Vesilehto
2025-08-25 23:08:21 +03:00
committed by GitHub
parent 5720d3ca7d
commit 9f7cc58d67
4 changed files with 15 additions and 1 deletions

View File

@@ -1,8 +1,13 @@
name: CIFuzz name: CIFuzz
on: on:
pull_request: pull_request:
branches: branches:
- master - master
permissions:
contents: read
jobs: jobs:
Fuzzing: Fuzzing:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View File

@@ -1,6 +1,11 @@
name: golangci-lint name: golangci-lint
on: on:
pull_request: pull_request:
permissions:
contents: read
jobs: jobs:
golangci: golangci:
name: lint name: lint

View File

@@ -4,7 +4,8 @@ on:
schedule: schedule:
- cron: '22 10 * * 0' - cron: '22 10 * * 0'
permissions: read-all permissions:
contents: read
jobs: jobs:
fix: fix:

View File

@@ -7,6 +7,9 @@ on:
description: "Commit (e.g., 52f0348)" description: "Commit (e.g., 52f0348)"
default: "master" default: "master"
permissions:
contents: read
jobs: jobs:
release: release:
name: Release name: Release