From d92e4ae42b79401b9a486e2a14176b4294c8db0b Mon Sep 17 00:00:00 2001 From: Don Naro Date: Thu, 4 Dec 2025 10:59:16 +0000 Subject: [PATCH] ci: fix issues identified by zizmor GHA linter (#3331) Co-authored-by: Maxwell G <9920591+gotmax23@users.noreply.github.com> (cherry picked from commit 8131b7ad32f9ec862473e7d8fd06358fc429815e) --- .github/workflows/ci.yaml | 3 +++ .github/workflows/labeler.yml | 5 +++++ .github/workflows/reusable-nox.yml | 2 ++ 3 files changed, 10 insertions(+) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index c52912470b2..efc652c57d1 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -11,6 +11,9 @@ on: pull_request: workflow_dispatch: +permissions: + contents: read + jobs: nox: uses: ./.github/workflows/reusable-nox.yml diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml index 79c24cfbc37..d2cd49e8c49 100644 --- a/.github/workflows/labeler.yml +++ b/.github/workflows/labeler.yml @@ -24,6 +24,9 @@ name: "Triage Issues and PRs" +permissions: + contents: read + jobs: label_prs: runs-on: ubuntu-latest @@ -43,6 +46,8 @@ jobs: private-key: ${{ secrets.BOT_APP_KEY }} - name: Checkout parent repository uses: actions/checkout@v4 + with: + persist-credentials: false - name: Install Python 3.11 uses: actions/setup-python@v5 with: diff --git a/.github/workflows/reusable-nox.yml b/.github/workflows/reusable-nox.yml index 7e2af505302..5e0a6e0c60c 100644 --- a/.github/workflows/reusable-nox.yml +++ b/.github/workflows/reusable-nox.yml @@ -36,6 +36,8 @@ jobs: steps: - name: Check out repo uses: actions/checkout@v4 + with: + persist-credentials: false - name: Setup nox uses: wntrblm/nox@2025.10.16 with: