diff --git a/.github/workflows/image_builds.yml b/.github/workflows/image_builds.yml index 007b1014..fe660754 100644 --- a/.github/workflows/image_builds.yml +++ b/.github/workflows/image_builds.yml @@ -5,6 +5,9 @@ on: branches: [ "master", "staging" ] workflow_dispatch: +permissions: + contents: read # to fetch code (actions/checkout) + jobs: docker_image_builds: strategy: diff --git a/.github/workflows/integration_tests.yml b/.github/workflows/integration_tests.yml index 7d6c4ac2..ee083bf4 100644 --- a/.github/workflows/integration_tests.yml +++ b/.github/workflows/integration_tests.yml @@ -5,6 +5,9 @@ on: branches: [ "master", "staging" ] workflow_dispatch: +permissions: + contents: read + jobs: integration_tests: runs-on: ubuntu-latest