diff --git a/.github/workflows/ocpl_cm_standards_check.yml b/.github/workflows/ocpl_cm_standards_check.yml index 1d5f3df..d4c08d9 100644 --- a/.github/workflows/ocpl_cm_standards_check.yml +++ b/.github/workflows/ocpl_cm_standards_check.yml @@ -6,4 +6,6 @@ on: jobs: commitlint_remote: - uses: nciocpl/.github/.github/workflows/ocpl_cm_standards_check.yml@workflow/v1 + permissions: + contents: read + uses: nciocpl/.github/.github/workflows/ocpl_cm_standards_check.yml@workflow/v2 diff --git a/.github/workflows/workflow.yml b/.github/workflows/workflow.yml index 0a4027c..32d9bf8 100644 --- a/.github/workflows/workflow.yml +++ b/.github/workflows/workflow.yml @@ -23,6 +23,10 @@ jobs: build: name: Build, Test and Upload Artifacts runs-on: ubuntu-22.04 + permissions: + contents: read + packages: read + pull-requests: write defaults: run: working-directory: ${{ format('./{0}', inputs.app_path) }} @@ -144,6 +148,8 @@ jobs: ## This job depends on build completing needs: build runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Download built app uses: actions/download-artifact@v4