diff --git a/.github/workflows/build-wheel.yml b/.github/workflows/build-wheel.yml index 56ccf23b33..627f5d4987 100644 --- a/.github/workflows/build-wheel.yml +++ b/.github/workflows/build-wheel.yml @@ -1,5 +1,7 @@ name: Build pip wheel +permissions: read-all + on: push: branches: [ "main" ] @@ -17,7 +19,7 @@ on: matrix: python-version: - "3.12" - if: github.repository == 'intel/cve-bin-tool' && github.ref == 'refs/heads/main' # run on origin repo only + if: github.repository == 'intel/cve-bin-tool' # run on origin repo only steps: - name: Harden Runner uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1 diff --git a/.github/workflows/testing.yml b/.github/workflows/testing.yml index 3a5e9781c2..935fbce7d7 100644 --- a/.github/workflows/testing.yml +++ b/.github/workflows/testing.yml @@ -1,5 +1,7 @@ name: Testing +permissions: read-all + on: push: pull_request: