diff --git a/.github/workflows/beta-java.yml b/.github/workflows/beta-java.yml index 212c890f..44f41bed 100644 --- a/.github/workflows/beta-java.yml +++ b/.github/workflows/beta-java.yml @@ -2,6 +2,8 @@ name: Beta Release (Java) on: workflow_dispatch: # Manual trigger ONLY +permissions: read-all + jobs: beta: runs-on: ubuntu-latest diff --git a/.github/workflows/ci-java.yml b/.github/workflows/ci-java.yml index 9fce4340..cdc31c93 100644 --- a/.github/workflows/ci-java.yml +++ b/.github/workflows/ci-java.yml @@ -6,9 +6,13 @@ on: pull_request: branches: [main] +permissions: read-all + jobs: build: runs-on: ubuntu-latest + permissions: + contents: read steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4.2.2 with: diff --git a/.github/workflows/release-java.yml b/.github/workflows/release-java.yml index bbabb535..ab36ec64 100644 --- a/.github/workflows/release-java.yml +++ b/.github/workflows/release-java.yml @@ -6,6 +6,8 @@ on: description: 'Release version (e.g., 0.1.0)' required: true +permissions: read-all + jobs: release: runs-on: ubuntu-latest