From be6bcbcfd31868d7d8cfb8b8f715210516b47085 Mon Sep 17 00:00:00 2001 From: Richard Smith Date: Wed, 24 Jun 2026 18:44:13 -0700 Subject: [PATCH] Narrow down overly-broad workflow permissions. (#7419) --- .github/workflows/gh_pages_deploy.yaml | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/.github/workflows/gh_pages_deploy.yaml b/.github/workflows/gh_pages_deploy.yaml index b7488c71da11..186e9a8d7713 100644 --- a/.github/workflows/gh_pages_deploy.yaml +++ b/.github/workflows/gh_pages_deploy.yaml @@ -18,15 +18,13 @@ concurrency: group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} cancel-in-progress: true -# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages. -permissions: - contents: read - pages: write - id-token: write +permissions: {} jobs: build: runs-on: ubuntu-latest + permissions: + contents: read steps: - name: Harden Runner uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1 @@ -72,6 +70,10 @@ jobs: url: ${{ steps.deployment.outputs.page_url }} runs-on: ubuntu-latest needs: build + # Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages. + permissions: + pages: write + id-token: write steps: - name: Harden Runner uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1