From af46584f826165687611d97c08dbecb8f1a0416b Mon Sep 17 00:00:00 2001
From: Ashish Kurmi <100655670+boahc077@users.noreply.github.com>
Date: Thu, 8 Sep 2022 00:44:24 -0700
Subject: [PATCH] ci: add minimum GitHub token permissions for workflows
 (#19138)

Signed-off-by: Ashish Kurmi <akurmi@stepsecurity.io>

Signed-off-by: Ashish Kurmi <akurmi@stepsecurity.io>
---
 .github/workflows/build-image.yml | 3 +++
 .github/workflows/check-i18n.yml  | 3 +++
 2 files changed, 6 insertions(+)

diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml
index 157c2fcde1..624aabbe7a 100644
--- a/.github/workflows/build-image.yml
+++ b/.github/workflows/build-image.yml
@@ -10,6 +10,9 @@ on:
     paths:
       - .github/workflows/build-image.yml
       - Dockerfile
+permissions:
+  contents: read
+
 jobs:
   build-image:
     runs-on: ubuntu-latest
diff --git a/.github/workflows/check-i18n.yml b/.github/workflows/check-i18n.yml
index 1c60515f8c..a9d8ea2eae 100644
--- a/.github/workflows/check-i18n.yml
+++ b/.github/workflows/check-i18n.yml
@@ -9,6 +9,9 @@ on:
 env:
   RAILS_ENV: test
 
+permissions:
+  contents: read
+
 jobs:
   check-i18n:
     runs-on: ubuntu-latest
-- 
GitLab