Set GitHub workflow permissions explicitly (#9432)

* Potential fix for code scanning alert no. 7: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 9: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 10: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 19: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Potential fix for code scanning alert no. 20: Workflow does not contain permissions

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* Set permissions in GitHub workflow jobs

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
Tim Visée
2026-06-11 16:02:12 +02:00
committed by GitHub
co-authored by Copilot Autofix powered by AI
parent 54be92ded0
commit 9acece1e2c
13 changed files with 45 additions and 0 deletions
+3
View File
@@ -5,6 +5,9 @@ on:
schedule:
- cron: "0 0 * * *" # Every day at midnight UTC
permissions:
contents: read
env:
UV_VERSION: 0.9.17
@@ -3,9 +3,15 @@ name: Build and push a branch gpu image to ghcr
on:
workflow_dispatch:
permissions:
contents: read
jobs:
branch-gpu-build-and-push:
runs-on: [self-hosted, linux, x64]
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -9,10 +9,16 @@ on:
repository_dispatch:
types: [benchmark-trigger-image-build]
permissions:
contents: read
jobs:
branch-build-and-push:
if: ${{ !github.event.client_payload.triggered }}
runs-on: [self-hosted, linux, x64]
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -30,6 +36,9 @@ jobs:
triggered-branch-build-and-push:
if: ${{ github.event.client_payload.triggered }}
runs-on: [self-hosted, linux, x64]
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -5,6 +5,8 @@ on:
schedule:
- cron: "0 0 * * *" # every day at midnight
permissions:
packages: write
jobs:
dev-clean-ghcr:
+2
View File
@@ -9,6 +9,8 @@ on:
default: false
required: true
permissions:
contents: read
jobs:
edge-py-linux:
+2
View File
@@ -9,6 +9,8 @@ on:
default: false
required: true
permissions:
contents: read
jobs:
edge-rust-check:
+3
View File
@@ -6,6 +6,9 @@ on:
pull_request:
branches: [ '**' ]
permissions:
contents: read
jobs:
edge-test:
name: Test Qdrant Edge
+3
View File
@@ -6,6 +6,9 @@ on:
pull_request:
branches: [ '**' ]
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
UV_VERSION: 0.9.17
@@ -13,6 +13,9 @@ on:
- "lib/common/common/src/universal_io/**"
- ".github/workflows/io-bridge-object-store-tests.yml"
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
+3
View File
@@ -5,6 +5,9 @@ on:
- cron: '30 6 * * *' # At 06:30
workflow_dispatch:
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
UV_VERSION: 0.9.17
+3
View File
@@ -5,6 +5,9 @@ on:
push:
branches: [ master ]
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
+3
View File
@@ -6,6 +6,9 @@ on:
pull_request:
branches: [ '**' ]
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
+3
View File
@@ -6,6 +6,9 @@ on:
pull_request:
branches: [ '**' ]
permissions:
contents: read
env:
CARGO_TERM_COLOR: always