From bdd6ab3addf56d47eed877101d8bad357e2c5fae Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cl=C3=A9ment=20Robert?= Date: Tue, 10 Mar 2026 13:14:38 +0100 Subject: [PATCH] SEC: disable default gha permissions (2/2) --- .github/workflows/pull_from_upstream.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/pull_from_upstream.yml b/.github/workflows/pull_from_upstream.yml index a143de35..c7cf7aa8 100644 --- a/.github/workflows/pull_from_upstream.yml +++ b/.github/workflows/pull_from_upstream.yml @@ -6,6 +6,8 @@ on: # Run every Saturday at 0900 UTC - cron: '0 9 * * 6' +permissions: {} + jobs: sync-workflows: if: github.repository != 'OpenAstronomy/github-actions-workflows'