Add empty permissions block at workflow level

Caps GITHUB_TOKEN's blast radius. None of these workflows need any
GitHub API write scope — they only push to Docker Hub — so the safest
default is permissions: {}, matching the posture used by AsamK/signal-cli.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Arne Huang 2026-05-09 10:00:28 -07:00
parent 419b18331d
commit 69457e8f81
3 changed files with 8 additions and 2 deletions

View File

@ -8,6 +8,8 @@ on:
branches:
- '**' #every branch
permissions: {}
jobs:
setup:
runs-on: ubuntu-24.04

View File

@ -4,9 +4,11 @@ on:
workflow_dispatch:
inputs:
version:
description: 'Version'
description: 'Version'
required: true
permissions: {}
jobs:
setup:

View File

@ -4,9 +4,11 @@ on:
workflow_dispatch:
inputs:
version:
description: 'Version'
description: 'Version'
required: true
permissions: {}
jobs:
setup: