From a133282fc361c9f13f0a710fe0c8df706141bf6a Mon Sep 17 00:00:00 2001 From: MHSanaei Date: Sun, 14 Jun 2026 21:09:00 +0200 Subject: [PATCH] ci(smoke): set least-privilege GITHUB_TOKEN permissions Add a top-level `permissions: contents: read` block so the smoke-test workflow no longer inherits the repository default token permissions. Resolves CodeQL actions/missing-workflow-permissions. --- .github/workflows/smoke.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/smoke.yml b/.github/workflows/smoke.yml index b9e89fc5f..dcb7ce590 100644 --- a/.github/workflows/smoke.yml +++ b/.github/workflows/smoke.yml @@ -15,6 +15,9 @@ on: - "deploy/**" - ".github/workflows/smoke.yml" +permissions: + contents: read + jobs: noninteractive-install: strategy: