diff --git a/.github/workflows/codacy-analysis.yml b/.github/workflows/codacy-analysis.yml index 81917e6b6a18..084f9266413e 100644 --- a/.github/workflows/codacy-analysis.yml +++ b/.github/workflows/codacy-analysis.yml @@ -17,9 +17,15 @@ on: schedule: - cron: '36 23 * * 3' +permissions: + contents: read + jobs: codacy-security-scan: # Ensure schedule job never runs on forked repos. It's only executed for 'snipe/snipe-it' + permissions: + contents: read # for actions/checkout to fetch code + security-events: write # for github/codeql-action/upload-sarif to upload SARIF results if: (github.repository == 'snipe/snipe-it') || ((github.repository != 'snipe/snipe-it') && (github.event_name != 'schedule')) name: Codacy Security Scan runs-on: ubuntu-latest diff --git a/.github/workflows/docker-alpine.yml b/.github/workflows/docker-alpine.yml index d0acba6fd77e..e922eb641f44 100644 --- a/.github/workflows/docker-alpine.yml +++ b/.github/workflows/docker-alpine.yml @@ -15,6 +15,9 @@ on: pull_request: +permissions: + contents: read + jobs: docker: # Ensure this job never runs on forked repos. It's only executed for 'snipe/snipe-it' diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 5df64f79f882..4a9610e1189f 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -15,6 +15,9 @@ on: pull_request: +permissions: + contents: read + jobs: docker: # Ensure this job never runs on forked repos. It's only executed for 'snipe/snipe-it'