diff --git a/.github/workflows/ci-e2e.yml b/.github/workflows/ci-e2e.yml index af0e2758d..96b0a4b26 100644 --- a/.github/workflows/ci-e2e.yml +++ b/.github/workflows/ci-e2e.yml @@ -3,6 +3,9 @@ name: E2E Tests on: workflow_call: +permissions: + contents: read + jobs: check-changes: name: Check web module changes diff --git a/.github/workflows/ci-quality.yml b/.github/workflows/ci-quality.yml index cc334fcaa..a81876d9d 100644 --- a/.github/workflows/ci-quality.yml +++ b/.github/workflows/ci-quality.yml @@ -3,6 +3,9 @@ name: Quality Checks on: workflow_call: +permissions: + contents: read + jobs: format: runs-on: ubuntu-latest diff --git a/.github/workflows/ci-scope-parity.yml b/.github/workflows/ci-scope-parity.yml index cffdeb341..8e2926ba8 100644 --- a/.github/workflows/ci-scope-parity.yml +++ b/.github/workflows/ci-scope-parity.yml @@ -28,6 +28,9 @@ name: Scope Resolution Parity on: workflow_call: +permissions: + contents: read + jobs: discover: name: Discover migrated languages diff --git a/.github/workflows/ci-tests.yml b/.github/workflows/ci-tests.yml index 7010ee6f3..b044d9318 100644 --- a/.github/workflows/ci-tests.yml +++ b/.github/workflows/ci-tests.yml @@ -3,6 +3,9 @@ name: Tests on: workflow_call: +permissions: + contents: read + jobs: tests: name: ubuntu / coverage diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3059a34dd..dd07337b7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -6,6 +6,9 @@ on: paths-ignore: ['**.md', 'docs/**', 'LICENSE'] workflow_call: +permissions: + contents: read + # Concurrency convention: see CONTRIBUTING.md → "GitHub Actions — Concurrency Convention". # Hardcoded `CI-` prefix (not `${{ github.workflow }}`) because this workflow is # invoked as a reusable workflow from publish.yml and release-candidate.yml. In diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index cfba3ecbc..fcafc0279 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -19,6 +19,9 @@ on: pull_request_review: types: [submitted] +permissions: + contents: read + # Concurrency convention: see CONTRIBUTING.md → "GitHub Actions — Concurrency Convention". # Serialize per-PR/issue to avoid racing comments. concurrency: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index d1dda8fb0..41f964cbe 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -17,6 +17,9 @@ on: # already-merged code without waiting for the next PR. - cron: '0 6 * * 1' +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index ad06267c2..1e2ba1f19 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -10,6 +10,9 @@ on: pull_request: branches: [main] +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 9e5750210..93dcf9ce3 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -26,6 +26,9 @@ on: required: true type: string +permissions: + contents: read + # Concurrency convention: see CONTRIBUTING.md → "GitHub Actions — Concurrency Convention". # Tag refs are unique per release, so distinct tags run in parallel. # Re-pushes of the same tag serialize. cancel-in-progress: false — never cancel a publish mid-flight. diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml index cfe4d0856..7cfc3bc52 100644 --- a/.github/workflows/gitleaks.yml +++ b/.github/workflows/gitleaks.yml @@ -12,6 +12,9 @@ on: push: branches: [main] +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} diff --git a/.github/workflows/pr-labeler.yml b/.github/workflows/pr-labeler.yml index 51664bba8..4a219bfab 100644 --- a/.github/workflows/pr-labeler.yml +++ b/.github/workflows/pr-labeler.yml @@ -35,6 +35,9 @@ on: pull_request_target: types: [opened, edited, reopened] +permissions: + contents: read + # Concurrency convention: see CONTRIBUTING.md → "GitHub Actions — Concurrency Convention". # Include `github.event_name` so `pull_request` (validate-title) and # `pull_request_target` (autolabel) runs for the same PR do NOT share a slot diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index d5af63205..0694b5e4c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -6,6 +6,7 @@ on: - 'v*' # No workflow-level permissions — scoped per job below. +permissions: {} # Concurrency convention: see CONTRIBUTING.md → "GitHub Actions — Concurrency Convention". # Tag refs are unique per release, so distinct tags run in parallel. Re-pushes of the diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index f7fba75e9..1251fa4dd 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -20,6 +20,9 @@ on: - cron: '0 8 * * 1' workflow_dispatch: +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: false diff --git a/.github/workflows/workflow-lint.yml b/.github/workflows/workflow-lint.yml index 7b38b8ddd..803c4d0bd 100644 --- a/.github/workflows/workflow-lint.yml +++ b/.github/workflows/workflow-lint.yml @@ -15,6 +15,9 @@ on: paths: - '.github/**' +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true