From f206880cf5a9c2670df18f806e4981f8c9e6eac1 Mon Sep 17 00:00:00 2001 From: Frazer Smith Date: Mon, 31 Mar 2025 15:28:10 +0100 Subject: [PATCH] ci: set workflow permissions to read-only by default --- .github/workflows/package-manager-ci.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/package-manager-ci.yml b/.github/workflows/package-manager-ci.yml index c6d598e..c38d060 100644 --- a/.github/workflows/package-manager-ci.yml +++ b/.github/workflows/package-manager-ci.yml @@ -14,6 +14,9 @@ on: - 'docs/**' - '*.md' +permissions: + contents: read + jobs: test: permissions: