diff --git a/.github/workflows/main-sonar-check.yml b/.github/workflows/main-sonar-check.yml index 429b0607552..527701debc1 100644 --- a/.github/workflows/main-sonar-check.yml +++ b/.github/workflows/main-sonar-check.yml @@ -22,6 +22,10 @@ on: branches: - main +permissions: + contents: read # to fetch code (actions/checkout) + pull-requests: write # for sonar to comment on pull-request + jobs: build: name: Main Sonar JaCoCo Build diff --git a/.github/workflows/sonar-check.yml b/.github/workflows/sonar-check.yml index 2bfdaf0a65f..54329bf47b1 100644 --- a/.github/workflows/sonar-check.yml +++ b/.github/workflows/sonar-check.yml @@ -26,6 +26,10 @@ concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true +permissions: + contents: read # to fetch code (actions/checkout) + pull-requests: write # for sonar to comment on pull-request + jobs: build: if: github.repository == 'apache/cloudstack'