diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index a592fb5c7..f381ba3aa 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -3,8 +3,13 @@ on: schedule: - cron: "30 0 * * *" +permissions: {} jobs: close-issues: + permissions: + issues: write # to close stale issues (actions/stale) + pull-requests: write # to close stale PRs (actions/stale) + runs-on: ubuntu-latest steps: - uses: actions/stale@v3 diff --git a/.github/workflows/submit.yml b/.github/workflows/submit.yml index 260176a65..4bc3ef514 100644 --- a/.github/workflows/submit.yml +++ b/.github/workflows/submit.yml @@ -2,6 +2,9 @@ name: "submit" on: workflow_dispatch: +permissions: + contents: read + jobs: build: runs-on: ubuntu-latest diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index e9041ab8f..f60cabe00 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -3,6 +3,9 @@ on: push: pull_request: +permissions: + contents: read # to fetch code (actions/checkout) + jobs: validate: name: Validate