ci: declare least-privilege permissions

none of the three declared any, so each got the repository default.
release.yml and docs.yml already do this. all three only check out,
build, test and upload artifacts.
This commit is contained in:
pj committed 2026-08-15 12:46:49 +05:30
1 parent 6605df5752
commit 7c845ff498
3 files changed
+9

No files matched your search

+3
View File
@@ -8,6 +8,9 @@ on:
pull_request: pull_request:
workflow_dispatch: workflow_dispatch:
permissions:
contents: read
concurrency: concurrency:
group: ci-${{ github.ref }} group: ci-${{ github.ref }}
cancel-in-progress: true cancel-in-progress: true
+3
View File
@@ -32,6 +32,9 @@ on:
description: step budget override (0 = each job's calibrated budget) description: step budget override (0 = each job's calibrated budget)
default: "0" default: "0"
permissions:
contents: read
jobs: jobs:
android: android:
timeout-minutes: 90 timeout-minutes: 90
+3
View File
@@ -19,6 +19,9 @@ on:
description: step budget for the dogfood run description: step budget for the dogfood run
default: "80" default: "80"
permissions:
contents: read
jobs: jobs:
dogfood: dogfood:
timeout-minutes: 45 timeout-minutes: 45