diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a7cef42..e6acff7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,6 +7,13 @@ on: pull_request: branches: [main] +# Least privilege for the default token, declared at the workflow level so every +# job inherits it; jobs that need more declare their own block below (this is +# what the CodeQL "Workflow does not contain permissions" rule asks for — see +# the re-anchor of PR #71's salvageable delta). +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.ref }} # A push to `main` QUEUES; a pull_request head update still cancels. @@ -43,6 +50,8 @@ jobs: repo-hygiene: name: Repo hygiene (licence · format · lint · commit) runs-on: ubuntu-24.04 + permissions: + contents: read continue-on-error: ${{ github.repository != 'hyperpolymath/MetaManifold-WebUI' }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -181,6 +190,8 @@ jobs: # for 24.04, and a runner that silently rolled to the next LTS would take that pin # with it. `runs-on` cannot read `env`, so this is a literal. runs-on: ubuntu-24.04 + permissions: + contents: read # The repository's root .Rprofile sources renv/activate.R, so R started from # the checkout auto-activates renv and rewrites the library paths. renv is a # local-development convenience; CI installs into the system library and