From 9acece1e2c6dafc052d6237739560666c88e317c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tim=20Vis=C3=A9e?= Date: Thu, 11 Jun 2026 16:02:12 +0200 Subject: [PATCH] Set GitHub workflow permissions explicitly (#9432) * Potential fix for code scanning alert no. 7: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Potential fix for code scanning alert no. 9: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Potential fix for code scanning alert no. 10: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Potential fix for code scanning alert no. 19: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Potential fix for code scanning alert no. 20: Workflow does not contain permissions Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * Set permissions in GitHub workflow jobs --------- Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- .github/workflows/coverage.yml | 3 +++ .github/workflows/dev-docker-image-build-gpu.yml | 6 ++++++ .github/workflows/dev-docker-image-build.yml | 9 +++++++++ .github/workflows/dev-docker-image-prune.yml | 2 ++ .github/workflows/edge-py-release.yml | 2 ++ .github/workflows/edge-rust-release.yml | 2 ++ .github/workflows/edge-test.yml | 3 +++ .github/workflows/integration-tests.yml | 3 +++ .github/workflows/io-bridge-object-store-tests.yml | 3 +++ .github/workflows/long-e2e-tests.yml | 3 +++ .github/workflows/rust-gpu.yml | 3 +++ .github/workflows/rust-lint.yml | 3 +++ .github/workflows/rust.yml | 3 +++ 13 files changed, 45 insertions(+) diff --git a/.github/workflows/coverage.yml b/.github/workflows/coverage.yml index 9fa53547ce..56783b1350 100644 --- a/.github/workflows/coverage.yml +++ b/.github/workflows/coverage.yml @@ -5,6 +5,9 @@ on: schedule: - cron: "0 0 * * *" # Every day at midnight UTC +permissions: + contents: read + env: UV_VERSION: 0.9.17 diff --git a/.github/workflows/dev-docker-image-build-gpu.yml b/.github/workflows/dev-docker-image-build-gpu.yml index b9466c2b35..ab8cb49be8 100644 --- a/.github/workflows/dev-docker-image-build-gpu.yml +++ b/.github/workflows/dev-docker-image-build-gpu.yml @@ -3,9 +3,15 @@ name: Build and push a branch gpu image to ghcr on: workflow_dispatch: +permissions: + contents: read + jobs: branch-gpu-build-and-push: runs-on: [self-hosted, linux, x64] + permissions: + contents: read + packages: write steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: diff --git a/.github/workflows/dev-docker-image-build.yml b/.github/workflows/dev-docker-image-build.yml index 9586c9ee5a..b645ceb5c1 100644 --- a/.github/workflows/dev-docker-image-build.yml +++ b/.github/workflows/dev-docker-image-build.yml @@ -9,10 +9,16 @@ on: repository_dispatch: types: [benchmark-trigger-image-build] +permissions: + contents: read + jobs: branch-build-and-push: if: ${{ !github.event.client_payload.triggered }} runs-on: [self-hosted, linux, x64] + permissions: + contents: read + packages: write steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: @@ -30,6 +36,9 @@ jobs: triggered-branch-build-and-push: if: ${{ github.event.client_payload.triggered }} runs-on: [self-hosted, linux, x64] + permissions: + contents: read + packages: write steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: diff --git a/.github/workflows/dev-docker-image-prune.yml b/.github/workflows/dev-docker-image-prune.yml index 2d3d5cf97f..f6da99dc7c 100644 --- a/.github/workflows/dev-docker-image-prune.yml +++ b/.github/workflows/dev-docker-image-prune.yml @@ -5,6 +5,8 @@ on: schedule: - cron: "0 0 * * *" # every day at midnight +permissions: + packages: write jobs: dev-clean-ghcr: diff --git a/.github/workflows/edge-py-release.yml b/.github/workflows/edge-py-release.yml index ce522c887d..6e7ef79df1 100644 --- a/.github/workflows/edge-py-release.yml +++ b/.github/workflows/edge-py-release.yml @@ -9,6 +9,8 @@ on: default: false required: true +permissions: + contents: read jobs: edge-py-linux: diff --git a/.github/workflows/edge-rust-release.yml b/.github/workflows/edge-rust-release.yml index 2dc6d5f9ad..5b460e92af 100644 --- a/.github/workflows/edge-rust-release.yml +++ b/.github/workflows/edge-rust-release.yml @@ -9,6 +9,8 @@ on: default: false required: true +permissions: + contents: read jobs: edge-rust-check: diff --git a/.github/workflows/edge-test.yml b/.github/workflows/edge-test.yml index c780fed32f..8fbd5080ac 100644 --- a/.github/workflows/edge-test.yml +++ b/.github/workflows/edge-test.yml @@ -6,6 +6,9 @@ on: pull_request: branches: [ '**' ] +permissions: + contents: read + jobs: edge-test: name: Test Qdrant Edge diff --git a/.github/workflows/integration-tests.yml b/.github/workflows/integration-tests.yml index 3f2c972716..afdd0f82e9 100644 --- a/.github/workflows/integration-tests.yml +++ b/.github/workflows/integration-tests.yml @@ -6,6 +6,9 @@ on: pull_request: branches: [ '**' ] +permissions: + contents: read + env: CARGO_TERM_COLOR: always UV_VERSION: 0.9.17 diff --git a/.github/workflows/io-bridge-object-store-tests.yml b/.github/workflows/io-bridge-object-store-tests.yml index 66a0fca78a..5d299affb4 100644 --- a/.github/workflows/io-bridge-object-store-tests.yml +++ b/.github/workflows/io-bridge-object-store-tests.yml @@ -13,6 +13,9 @@ on: - "lib/common/common/src/universal_io/**" - ".github/workflows/io-bridge-object-store-tests.yml" +permissions: + contents: read + env: CARGO_TERM_COLOR: always diff --git a/.github/workflows/long-e2e-tests.yml b/.github/workflows/long-e2e-tests.yml index 081093c454..e40141d8a2 100644 --- a/.github/workflows/long-e2e-tests.yml +++ b/.github/workflows/long-e2e-tests.yml @@ -5,6 +5,9 @@ on: - cron: '30 6 * * *' # At 06:30 workflow_dispatch: +permissions: + contents: read + env: CARGO_TERM_COLOR: always UV_VERSION: 0.9.17 diff --git a/.github/workflows/rust-gpu.yml b/.github/workflows/rust-gpu.yml index 4edce11756..496e13caaa 100644 --- a/.github/workflows/rust-gpu.yml +++ b/.github/workflows/rust-gpu.yml @@ -5,6 +5,9 @@ on: push: branches: [ master ] +permissions: + contents: read + env: CARGO_TERM_COLOR: always diff --git a/.github/workflows/rust-lint.yml b/.github/workflows/rust-lint.yml index c7eed4cc6d..e6270dfda0 100644 --- a/.github/workflows/rust-lint.yml +++ b/.github/workflows/rust-lint.yml @@ -6,6 +6,9 @@ on: pull_request: branches: [ '**' ] +permissions: + contents: read + env: CARGO_TERM_COLOR: always diff --git a/.github/workflows/rust.yml b/.github/workflows/rust.yml index dbf67db512..9764c6e2c4 100644 --- a/.github/workflows/rust.yml +++ b/.github/workflows/rust.yml @@ -6,6 +6,9 @@ on: pull_request: branches: [ '**' ] +permissions: + contents: read + env: CARGO_TERM_COLOR: always