From 1d1aa791cea20ffc159a46556a58335841242ec5 Mon Sep 17 00:00:00 2001 From: Ryan Inch Date: Mon, 6 Jul 2026 03:51:19 -0400 Subject: [PATCH] Restrict ret-turkey workflow to minimum required permissions What: sets the permissions of the ret-turkey workflow to none. Why: to minimize the chance of the workflow being hacked and in preparation to globally restrict permissions for all Hubs Foundation workflows. Note: the permissions setting was advised by `GitHubSecurityLab/actions-permissions/monitor@bf82d13b9b10051d224345ab9184f5ede0a94289 #v1 Beta 9` --- .github/workflows/ret-turkey.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/ret-turkey.yml b/.github/workflows/ret-turkey.yml index 9cf9cdf1a..b363e6adc 100644 --- a/.github/workflows/ret-turkey.yml +++ b/.github/workflows/ret-turkey.yml @@ -7,6 +7,8 @@ on: paths-ignore: [".github/**", "guides/**", "README.md", "LICENSE", "CODE_OF_CONDUCT.md"] workflow_dispatch: +permissions: {} + jobs: turkeyGitops: if: github.repository_owner == 'Hubs-Foundation'