diff --git a/.github/workflows/wasm-release.yml b/.github/workflows/wasm-release.yml
index 255de7dc5..c34571784 100644
--- a/.github/workflows/wasm-release.yml
+++ b/.github/workflows/wasm-release.yml
@@ -12,6 +12,9 @@ defaults:
 env:
   EM_VERSION: 3.1.15
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
   publish:
     name: Publish
diff --git a/.github/workflows/wasm.yml b/.github/workflows/wasm.yml
index bd76c8033..418438635 100644
--- a/.github/workflows/wasm.yml
+++ b/.github/workflows/wasm.yml
@@ -12,6 +12,9 @@ defaults:
 env:
   EM_VERSION: 3.1.15
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
   check:
     name: Check