Add empty permissions block at workflow level

Caps GITHUB_TOKEN's blast radius. None of these workflows need any
GitHub API write scope — they only push to Docker Hub — so the safest
default is permissions: {}, matching the posture used by AsamK/signal-cli.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Arne Huang 2026-05-09 10:00:28 -07:00
parent 419b18331d
commit 69457e8f81
3 changed files with 8 additions and 2 deletions

View File

@ -8,6 +8,8 @@ on:
branches: branches:
- '**' #every branch - '**' #every branch
permissions: {}
jobs: jobs:
setup: setup:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04

View File

@ -7,6 +7,8 @@ on:
description: 'Version' description: 'Version'
required: true required: true
permissions: {}
jobs: jobs:
setup: setup:

View File

@ -7,6 +7,8 @@ on:
description: 'Version' description: 'Version'
required: true required: true
permissions: {}
jobs: jobs:
setup: setup: