From 7eec8caae38d290d6842b3f8865a1d216499a26e Mon Sep 17 00:00:00 2001 From: El RIDO Date: Fri, 10 Oct 2025 15:07:44 +0200 Subject: [PATCH] apply explicit permissions as per CodeQL suggestion as per rule ID actions/missing-workflow-permissions --- .github/workflows/codeql-analysis.yml | 4 ++++ .github/workflows/release.yml | 4 ++++ .github/workflows/snyk-scan.yml | 5 +++++ .github/workflows/tests.yml | 3 +++ codacy-analysis.yml | 4 ++++ 5 files changed, 20 insertions(+) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b212c2a3..ec6b7f57 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -18,6 +18,10 @@ on: schedule: - cron: '28 22 * * 5' +permissions: + contents: read + security-events: write + jobs: analyze: name: Analyze diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index bb396de5..d347a6fb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -4,8 +4,12 @@ on: push: tags: '[0-9]+.[0-9]?[0-9]?[0-9]?.?[0-9]+' +permissions: {} + jobs: draft: + permissions: + contents: write runs-on: ubuntu-latest steps: - name: Fetch changelog from tag diff --git a/.github/workflows/snyk-scan.yml b/.github/workflows/snyk-scan.yml index 7b060a21..74787b35 100644 --- a/.github/workflows/snyk-scan.yml +++ b/.github/workflows/snyk-scan.yml @@ -8,6 +8,11 @@ on: branches: [ master ] pull_request: branches: [ master ] + +permissions: + contents: read + security-events: write + jobs: # https://github.com/snyk/actions/tree/master/php snyk-php: diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 682725d6..9de42a04 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -1,8 +1,11 @@ name: Tests + on: push: workflow_dispatch: +permissions: {} + jobs: Composer: diff --git a/codacy-analysis.yml b/codacy-analysis.yml index 31d065cd..ab98e9ad 100644 --- a/codacy-analysis.yml +++ b/codacy-analysis.yml @@ -17,6 +17,10 @@ on: schedule: - cron: '45 16 * * 1' +permissions: + contents: read + security-events: write + jobs: codacy-security-scan: name: Codacy Security Scan