From 05f6cb7b79a8d8381cc379d2580b28e843404434 Mon Sep 17 00:00:00 2001 From: Adnan Khan Date: Mon, 20 Oct 2025 18:11:00 -0400 Subject: [PATCH] Scope down GitHub token permissions for go.yml Signed-off-by: Adnan Khan --- .github/workflows/go.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index a1737e99..ab574e85 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -6,6 +6,10 @@ on: pull_request: branches: [ main ] + +permissions: + contents: read + jobs: build: