From 85ef5979821df49a31a5e8e233b1cf634d39a36e Mon Sep 17 00:00:00 2001 From: MacOS Date: Thu, 30 Jul 2026 10:14:59 +0200 Subject: [PATCH 1/2] build(engine-benchmarks): set contents permission to read on workflow level --- .github/workflows/engine-benchmarks.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/engine-benchmarks.yml b/.github/workflows/engine-benchmarks.yml index 9a2e7533c..f0f3f91ab 100644 --- a/.github/workflows/engine-benchmarks.yml +++ b/.github/workflows/engine-benchmarks.yml @@ -34,6 +34,10 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true +# Set contents permission to read, all others are set to none automatically +permissions: + contents: read + jobs: smoke-ubuntu-latest: # Smoke pack on the default GitHub runner. Goal: prove the harness + From 2204abb9d18987abe132aa58115d074ec075f9b4 Mon Sep 17 00:00:00 2001 From: Michal Harakal Date: Tue, 11 Aug 2026 12:25:37 +0200 Subject: [PATCH 2/2] fix(engine-benchmarks): restore workflow-level permissions: {} The merge conflict resolution with develop kept this PR's original top-level `contents: read`, dropping develop's `permissions: {}` (from e187c15d) that every other workflow now follows. Both jobs already declare their own `contents: read`, so behavior is unchanged, but the fail-safe default matters for any job added later. --- .github/workflows/engine-benchmarks.yml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/engine-benchmarks.yml b/.github/workflows/engine-benchmarks.yml index 5b58bdee7..f36230953 100644 --- a/.github/workflows/engine-benchmarks.yml +++ b/.github/workflows/engine-benchmarks.yml @@ -34,9 +34,8 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true -# Set contents permission to read, all others are set to none automatically -permissions: - contents: read +# Set default permission for all jobs to none +permissions: {} jobs: smoke-ubuntu-latest: