Judging by https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token
it should be enough to grant the "read contents" permission to
most of our actions. The "read metadata" permission is set impliciclty
somewhere and can't be set via the "permissions" setting:
```
The workflow is not valid. .github/workflows/linter.yml (Line: 14, Col: 3): Unexpected value 'metadata'
```
- 'src/**'
- 'test/fuzz/**'
-permissions: read-all
+permissions:
+ contents: read
jobs:
build:
name: CIFuzz
-permissions: read-all
+permissions:
+ contents: read
on:
pull_request:
# Run Coverity daily at midnight
- cron: '0 0 * * *'
-permissions: read-all
+permissions:
+ contents: read
jobs:
build:
- main
- v[0-9]+-stable
-permissions: read-all
+permissions:
+ contents: read
jobs:
build:
- main
- v[0-9]+-stable
-permissions: read-all
+permissions:
+ contents: read
jobs:
ci:
- main
- v[0-9]+-stable
-permissions: read-all
+permissions:
+ contents: read
jobs:
build: