From ef98898635b4873c9191bbe33d9319e971a00312 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 23 Jul 2026 14:59:43 -0400 Subject: [PATCH] ci: add least-privilege permissions blocks to workflow callers Resolves code scanning alerts #4 and #5 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match. --- .github/workflows/ci.yaml | 3 +++ .github/workflows/dependency-review.yml | 4 ++++ 2 files changed, 7 insertions(+) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index e4be9ff..2388fb5 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -3,6 +3,9 @@ on: pull_request: branches: [main] +permissions: + contents: read + jobs: ci: uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 2cd8119..42002bb 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,6 +1,10 @@ name: Dependency Review on: pull_request: + +permissions: + contents: read + jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main