diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a1347724da6..4dcae6d29b5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,6 +1,9 @@ name: Run unit tests on: [push, pull_request] +permissions: + contents: read + jobs: lint: name: Check PHP syntax @@ -42,6 +45,8 @@ jobs: - run: | git ls-files | grep \\\.php$ | grep -v ^dictionaries/scripts/* | ./vendor/bin/parallel-lint --stdin chunk-matrix: + permissions: + contents: none name: Generate Chunk Matrix runs-on: ubuntu-latest diff --git a/.github/workflows/shepherd.yml b/.github/workflows/shepherd.yml index 1ff14195871..b60bca06d65 100644 --- a/.github/workflows/shepherd.yml +++ b/.github/workflows/shepherd.yml @@ -2,6 +2,9 @@ name: Run Shepherd on: [push, pull_request] +permissions: + contents: read + jobs: build: runs-on: ubuntu-latest diff --git a/.github/workflows/windows-ci.yml b/.github/workflows/windows-ci.yml index dc5fd77c560..b901fcdf8fc 100644 --- a/.github/workflows/windows-ci.yml +++ b/.github/workflows/windows-ci.yml @@ -2,8 +2,13 @@ name: Run unit tests on Windows on: [push, pull_request] +permissions: + contents: read + jobs: chunk-matrix: + permissions: + contents: none name: Generate Chunk Matrix runs-on: ubuntu-latest