diff --git a/.github/workflows/changelog.yml b/.github/workflows/changelog.yml index cc90d97..f463c57 100644 --- a/.github/workflows/changelog.yml +++ b/.github/workflows/changelog.yml @@ -10,6 +10,8 @@ concurrency: group: ${{ github.ref }} cancel-in-progress: true +permissions: read-all + jobs: build: runs-on: ubuntu-22.04 diff --git a/.github/workflows/jsonlint.yml b/.github/workflows/jsonlint.yml index 791f1f3..14a1679 100644 --- a/.github/workflows/jsonlint.yml +++ b/.github/workflows/jsonlint.yml @@ -6,6 +6,8 @@ on: branches: - main +permissions: read-all + jobs: format-json: name: Format JSON files and create a pull request diff --git a/.github/workflows/shellcheck-markdown.yml b/.github/workflows/shellcheck-markdown.yml index ccd7a5d..de953a9 100644 --- a/.github/workflows/shellcheck-markdown.yml +++ b/.github/workflows/shellcheck-markdown.yml @@ -4,6 +4,8 @@ name: Shellcheck code in Markdown on: [push] +permissions: read-all + jobs: build: runs-on: ubuntu-22.04 diff --git a/.github/workflows/super-linter.yml b/.github/workflows/super-linter.yml index 78deebc..2b95cb7 100644 --- a/.github/workflows/super-linter.yml +++ b/.github/workflows/super-linter.yml @@ -23,6 +23,11 @@ concurrency: group: ${{ github.ref }} cancel-in-progress: true +############################ +# Ensure safer permissions # +############################ +permissions: read-all + ############### # Set the Job # ############### @@ -50,7 +55,7 @@ jobs: # Run Linter against code base # ################################ - name: Lint Code Base - uses: super-linter/super-linter@v5 + uses: super-linter/super-linter@v6 env: VALIDATE_ALL_CODEBASE: false DEFAULT_BRANCH: main