From 672315eb993d27d74322e9fc54775a57489aa177 Mon Sep 17 00:00:00 2001 From: Arpit Jain Date: Tue, 26 May 2026 07:48:43 +0900 Subject: [PATCH] ci(validate): cap GITHUB_TOKEN to contents: read validate workflow runs landscape validation only; no GitHub API writes. Signed-off-by: Arpit Jain --- .github/workflows/validate.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 6547f36bc45..7a6cf96372a 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -7,6 +7,9 @@ on: - main - master +permissions: + contents: read + jobs: validate-landscape: runs-on: ubuntu-latest