ci: add least-privilege permissions blocks to workflow callers

Resolves code scanning alerts #4 and #5 (actions/missing-workflow-permissions). Both callable workflows only need contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
This commit is contained in:
Adam Moussa 2026-07-23 16:14:18 -04:00
parent bf235e70d7
commit 2a98bd51bb
No known key found for this signature in database
2 changed files with 7 additions and 0 deletions

View file

@ -3,6 +3,9 @@ on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main

View file

@ -1,6 +1,10 @@
name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@fd60e4c9041784f666ac0fdefb9bec3c7fbf5143 # main