Skip to content

Commit b398037

Browse files
[CI] Use least privileged tokens by default in workflows
1 parent 8b15a5d commit b398037

File tree

2 files changed

+8
-4
lines changed

2 files changed

+8
-4
lines changed

.github/workflows/benchmarks.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29,11 +29,13 @@ on:
2929
- L0_PERF
3030

3131
permissions:
32-
contents: write
33-
pull-requests: write
32+
contents: read
3433

3534
jobs:
3635
manual:
36+
permissions:
37+
contents: write
38+
pull-requests: write
3739
name: Compute Benchmarks
3840
uses: ./.github/workflows/reusable_benchmarks.yml
3941
with:

.github/workflows/reusable_benchmarks.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,7 @@ on:
2424
default: 'L0_PERF'
2525

2626
permissions:
27-
contents: write
28-
pull-requests: write
27+
contents: read
2928

3029
env:
3130
UMF_DIR: "${{github.workspace}}/umf-repo"
@@ -37,6 +36,9 @@ jobs:
3736
# run only on upstream; forks will not have the HW
3837
if: github.repository == 'oneapi-src/unified-memory-framework'
3938
runs-on: ${{ inputs.runner }}
39+
permissions:
40+
contents: write
41+
pull-requests: write
4042

4143
steps:
4244
- name: Establish bench params

0 commit comments

Comments
 (0)