diff --git a/.github/workflows/govulncheck.yml b/.github/workflows/govulncheck.yml index d326a772f2..58ad384559 100644 --- a/.github/workflows/govulncheck.yml +++ b/.github/workflows/govulncheck.yml @@ -8,6 +8,9 @@ on: env: GO_VERSION: "^1.21" +permissions: + contents: read + jobs: ci-security-checks: runs-on: ubuntu-latest diff --git a/.github/workflows/semantic.yml b/.github/workflows/semantic.yml index 71bc8cd4e2..c2f6094adb 100644 --- a/.github/workflows/semantic.yml +++ b/.github/workflows/semantic.yml @@ -7,8 +7,14 @@ on: - edited - synchronize +permissions: + contents: read + jobs: main: + permissions: + pull-requests: read # for amannn/action-semantic-pull-request to analyze PRs + statuses: write # for amannn/action-semantic-pull-request to mark status of analyzed PR name: Validate PR title for semantic commit message runs-on: ubuntu-latest steps: