diff --git a/.github/workflows/codacy-analysis.yml b/.github/workflows/codacy-analysis.yml index 920224d3..f00965a0 100644 --- a/.github/workflows/codacy-analysis.yml +++ b/.github/workflows/codacy-analysis.yml @@ -17,6 +17,10 @@ on: schedule: - cron: '45 16 * * 1' +permissions: + contents: read + security-events: write + jobs: codacy-security-scan: name: Codacy Security Scan diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b212c2a3..ec6b7f57 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -18,6 +18,10 @@ on: schedule: - cron: '28 22 * * 5' +permissions: + contents: read + security-events: write + jobs: analyze: name: Analyze diff --git a/.github/workflows/eslint.yml b/.github/workflows/eslint.yml index 7b6c30d0..6324c160 100644 --- a/.github/workflows/eslint.yml +++ b/.github/workflows/eslint.yml @@ -1,6 +1,4 @@ name: ESLint Check -permissions: - contents: read on: push: @@ -14,6 +12,9 @@ on: - 'js/package-lock.json' - .github/workflows/eslint.yml +permissions: + contents: read + jobs: eslint: runs-on: ubuntu-latest diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index bb396de5..d347a6fb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -4,8 +4,12 @@ on: push: tags: '[0-9]+.[0-9]?[0-9]?[0-9]?.?[0-9]+' +permissions: {} + jobs: draft: + permissions: + contents: write runs-on: ubuntu-latest steps: - name: Fetch changelog from tag diff --git a/.github/workflows/snyk-scan.yml b/.github/workflows/snyk-scan.yml index e48dfa08..2dc75680 100644 --- a/.github/workflows/snyk-scan.yml +++ b/.github/workflows/snyk-scan.yml @@ -8,6 +8,11 @@ on: branches: [ master ] pull_request: branches: [ master ] + +permissions: + contents: read + security-events: write + jobs: # https://github.com/snyk/actions/tree/master/php snyk-php: diff --git a/.github/workflows/test-results.yml b/.github/workflows/test-results.yml index 2a315b7a..c918e4fa 100644 --- a/.github/workflows/test-results.yml +++ b/.github/workflows/test-results.yml @@ -5,6 +5,7 @@ on: workflows: ["Tests"] types: - completed + permissions: {} jobs: diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index a33660b2..cc5dbe33 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -1,10 +1,13 @@ name: Tests + on: push: pull_request: branches: [ master ] workflow_dispatch: +permissions: {} + jobs: Composer: