fix: set minimal top-level permissions on workflows (#14358)

- Fix CodeQL alerts by declaring read-only GITHUB_TOKEN scope at the
workflow level. The codespace image publish workflow additionally needs
packages: write to push to ghcr.io.
This commit is contained in:
Vishnu Narayanan
2026-05-04 17:56:25 +05:30
committed by GitHub
parent ea87610999
commit 2dee7457cd
9 changed files with 28 additions and 0 deletions
+3
View File
@@ -11,6 +11,9 @@ concurrency:
group: pr-${{ github.workflow }}-${{ github.head_ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
deployment_check:
name: Check Deployment