From f88bf92aaf9552b0a6a2e88a001e713e388dfc69 Mon Sep 17 00:00:00 2001 From: Alejo Amiras Date: Wed, 30 Sep 2026 13:10:51 +0000 Subject: [PATCH] ci: default the test workflows' token to contents: read pr-checks.yml and main-tests.yml set no permissions, so every job without its own block (format, and the run-tests.yml calls) got the repository's default token. That default is read-only today, but nothing in the workflows pins it. A workflow-level `contents: read` covers those jobs; `changes` and `benchmark` keep their own blocks. Resolves CodeQL actions/missing-workflow-permissions alerts #2, #3, #4. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/main-tests.yml | 3 +++ .github/workflows/pr-checks.yml | 3 +++ 2 files changed, 6 insertions(+) diff --git a/.github/workflows/main-tests.yml b/.github/workflows/main-tests.yml index 919252df..a72958aa 100644 --- a/.github/workflows/main-tests.yml +++ b/.github/workflows/main-tests.yml @@ -9,6 +9,9 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true +permissions: + contents: read + jobs: tests: uses: AztecProtocol/aztec-ci-actions/.github/workflows/run-tests.yml@431859e477234b8690eb1f80d1305d2e34f10f1b # v0.1.1 diff --git a/.github/workflows/pr-checks.yml b/.github/workflows/pr-checks.yml index 3053f025..e002f030 100644 --- a/.github/workflows/pr-checks.yml +++ b/.github/workflows/pr-checks.yml @@ -7,6 +7,9 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number }} cancel-in-progress: true +permissions: + contents: read + jobs: # Job-level gating (not workflow-level `paths:`) so a skipped benchmark still # reports as passing for branch protection.