diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b212c2a3..ec6b7f57 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -18,6 +18,10 @@ on: schedule: - cron: '28 22 * * 5' +permissions: + contents: read + security-events: write + jobs: analyze: name: Analyze diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index bb396de5..d347a6fb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -4,8 +4,12 @@ on: push: tags: '[0-9]+.[0-9]?[0-9]?[0-9]?.?[0-9]+' +permissions: {} + jobs: draft: + permissions: + contents: write runs-on: ubuntu-latest steps: - name: Fetch changelog from tag diff --git a/.github/workflows/snyk-scan.yml b/.github/workflows/snyk-scan.yml index 7b060a21..74787b35 100644 --- a/.github/workflows/snyk-scan.yml +++ b/.github/workflows/snyk-scan.yml @@ -8,6 +8,11 @@ on: branches: [ master ] pull_request: branches: [ master ] + +permissions: + contents: read + security-events: write + jobs: # https://github.com/snyk/actions/tree/master/php snyk-php: diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 682725d6..9de42a04 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -1,8 +1,11 @@ name: Tests + on: push: workflow_dispatch: +permissions: {} + jobs: Composer: diff --git a/codacy-analysis.yml b/codacy-analysis.yml index 31d065cd..ab98e9ad 100644 --- a/codacy-analysis.yml +++ b/codacy-analysis.yml @@ -17,6 +17,10 @@ on: schedule: - cron: '45 16 * * 1' +permissions: + contents: read + security-events: write + jobs: codacy-security-scan: name: Codacy Security Scan