From 7a3372fc3f122003d3f675ddcec681cabbae868a Mon Sep 17 00:00:00 2001 From: Varun Sharma Date: Wed, 31 Aug 2022 15:50:47 -0700 Subject: [PATCH] [GitHub] Add minimum GitHub token permissions for workflows Signed-off-by: Varun Sharma --- .github/workflows/codeql-analysis.yml | 3 +++ .github/workflows/stale-action.yml | 6 ++++++ 2 files changed, 9 insertions(+) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index f228d3fad24..c671770c770 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -9,6 +9,9 @@ on: schedule: - cron: '22 1 * * 2' +permissions: + contents: read + jobs: analyze: name: Analyze diff --git a/.github/workflows/stale-action.yml b/.github/workflows/stale-action.yml index c73c129c489..2ae741ebffd 100644 --- a/.github/workflows/stale-action.yml +++ b/.github/workflows/stale-action.yml @@ -3,8 +3,14 @@ on: schedule: - cron: "0 0 * * *" +permissions: + contents: read + jobs: stale: + permissions: + issues: write # for actions/stale to close stale issues + pull-requests: write # for actions/stale to close stale PRs runs-on: ubuntu-latest steps: - uses: actions/stale@v4