diff --git a/.github/workflows/docker_main.yml b/.github/workflows/docker_main.yml index 94eadaf72..e15025278 100644 --- a/.github/workflows/docker_main.yml +++ b/.github/workflows/docker_main.yml @@ -8,12 +8,13 @@ on: - '.github/**' # exclude .github directory - '**.md' # exclude all markdown files +permissions: + contents: read + packages: write + jobs: docker: runs-on: ubuntu-latest - permissions: - contents: read - packages: write steps: - uses: actions/checkout@v3 with: diff --git a/.github/workflows/docker_release.yml b/.github/workflows/docker_release.yml index 11a5c311a..181781b2a 100644 --- a/.github/workflows/docker_release.yml +++ b/.github/workflows/docker_release.yml @@ -4,13 +4,14 @@ on: release: types: [released, prereleased] +permissions: + contents: read + packages: write + jobs: docker: runs-on: ubuntu-latest - permissions: - contents: read - packages: write steps: - uses: actions/checkout@v4 with: diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index b37a48995..5495a8053 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -7,6 +7,10 @@ on: pull_request: release: types: [released] + +permissions: + contents: write + jobs: build: runs-on: ubuntu-latest diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index b3a754fea..47b5a99b0 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -2,7 +2,7 @@ name: Go on: push: - branches: [main] + branches: [main] paths: - '**' # include all files - '!.github/**' # exclude .github directory @@ -18,6 +18,10 @@ on: workflow_dispatch: +permissions: + contents: read + packages: write + jobs: build: env: diff --git a/.github/workflows/integration.yml b/.github/workflows/integration.yml index cba43d3df..256b3bc77 100644 --- a/.github/workflows/integration.yml +++ b/.github/workflows/integration.yml @@ -7,6 +7,9 @@ on: - cron: "0 0 * * *" workflow_dispatch: +permissions: + contents: read + jobs: e2e-test: runs-on: firefly-ubuntu-latest diff --git a/.github/workflows/solidity.yml b/.github/workflows/solidity.yml index 47ebecd61..bd69f84ec 100644 --- a/.github/workflows/solidity.yml +++ b/.github/workflows/solidity.yml @@ -4,6 +4,10 @@ on: pull_request: branches: [main] +permissions: + contents: read + packages: read + jobs: solidity-test: runs-on: ubuntu-latest