diff --git a/.github/workflows/build-devcontainer-image.yml b/.github/workflows/build-devcontainer-image.yml index 38b6c46fc84..63013cfce55 100644 --- a/.github/workflows/build-devcontainer-image.yml +++ b/.github/workflows/build-devcontainer-image.yml @@ -24,6 +24,9 @@ jobs: packages: write contents: read + # Only run this scheduled job on the main repo, it can't work elsewhere + if: ${{ github.repository == 'Azure/azure-service-operator' }} + steps: - name: Checkout code uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # pinned to 4.1.7 diff --git a/.github/workflows/scan-controller-image.yaml b/.github/workflows/scan-controller-image.yaml index 29c59eb7876..00888f8118c 100644 --- a/.github/workflows/scan-controller-image.yaml +++ b/.github/workflows/scan-controller-image.yaml @@ -18,9 +18,13 @@ on: jobs: scan-image: runs-on: ubuntu-latest + permissions: packages: read + # Only run this scheduled job on the main repo, it can't work elsewhere + if: ${{ github.repository == 'Azure/azure-service-operator' }} + steps: - name: Checkout code uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # pinned to 4.1.7