feat: Restrict permissions in reusable workflows (#421)
### feat: Restrict permissions in reusable workflows
This update limits the `GITHUB_TOKEN` permissions granted to reusable workflows, ensuring they operate with only the permissions strictly necessary for their function.
Although GitHub ensures that reusable workflows cannot exceed the permissions granted by the calling workflow, [GitHub documentation](https://docs.github.com/en/actions/sharing-automations/reusing-workflows#access-and-permissions) recommends that they explicitly declare the minimal permissions they require. This practice helps prevent misuse in scenarios where a caller might over-provision permissions.
#### 🔐 Updated Permissions by Workflow:
- **`contents: write`**
Required only by:
- `deploy-release-reusable`
- `deploy-site-reusable`
These workflows need write access to push changes to Git branches.
For all other workflows, we now explicitly set `contents: none`.
- **`security-events: write`**
Required only by:
- `codeql-analysis-reusable`
- `scorecards-analysis-reusable`
These workflows need this permission to upload security scanning results.
By scoping permissions tightly, we improve our workflows’ security posture without impacting functionality.
* Remove `profile: ~`
### fix: Clarify workflow-level `permissions` setting
Add a comment explaining that setting `permissions` at the workflow level defines the **default** permissions for all jobs.
To enforce the principle of least privilege, the default is set to `{}` (no permissions), requiring each job to explicitly declare only what it needs.
Co-authored-by: Volkan Yazıcı <volkan@yazi.ci>13 files changed