diff --git a/.github/workflows/build-check.yml b/.github/workflows/build-check.yml index b9096601..fd17458b 100644 --- a/.github/workflows/build-check.yml +++ b/.github/workflows/build-check.yml @@ -6,6 +6,9 @@ on: branches: - main +permissions: + contents: read + jobs: compile: strategy: diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index e38d408b..fc85e589 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -12,6 +12,11 @@ concurrency: group: codeql-${{ github.ref_name }} cancel-in-progress: true +permissions: + actions: read + contents: read + security-events: write # github/codeql-action/upload posts SARIF results + jobs: codeql-analyze: runs-on: ubuntu-latest