have the workflow run with read-only permissions
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml
index d4ae3d0..2fa7dbe 100644
--- a/.github/workflows/build.yaml
+++ b/.github/workflows/build.yaml
@@ -6,6 +6,8 @@
   pull_request:
     branches: [ master ]
 
+permissions: read-all
+
 jobs:
   build:
     runs-on: ubuntu-latest