Commit 46847e615 for llama.cpp

commit 46847e61582097979f539595d893d83d8e1d1af1
Author: Sigbjørn Skjæret <sigbjorn.skjaeret@huggingface.co>
Date:   Sun Oct 4 16:13:26 2026 +0200

    ci : set default permissions (#29945)

diff --git a/.github/workflows/ai-issues.yml b/.github/workflows/ai-issues.yml
index c762901b5..3f01ea856 100644
--- a/.github/workflows/ai-issues.yml
+++ b/.github/workflows/ai-issues.yml
@@ -4,6 +4,10 @@ on:
   issues:
     types: [opened]

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
   find-related:
     if: github.event.action == 'opened'
diff --git a/.github/workflows/build-3rd-party.yml b/.github/workflows/build-3rd-party.yml
index 82e53dbaf..fe25f3909 100644
--- a/.github/workflows/build-3rd-party.yml
+++ b/.github/workflows/build-3rd-party.yml
@@ -15,6 +15,10 @@ on:
       '**/*.cpp'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-and-test-snapdragon.yml b/.github/workflows/build-and-test-snapdragon.yml
index 296780acb..d6420b65f 100644
--- a/.github/workflows/build-and-test-snapdragon.yml
+++ b/.github/workflows/build-and-test-snapdragon.yml
@@ -23,6 +23,10 @@ on:
       - 'scripts/snapdragon/**'
       - 'CMakePresets.json'

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -36,6 +40,10 @@ jobs:
       run:
         shell: bash

+    permissions:
+      actions: write
+      contents: read
+
     steps:
       - name: Clone
         uses: actions/checkout@v6
@@ -66,6 +74,10 @@ jobs:
       run:
         shell: bash

+    permissions:
+      actions: write
+      contents: read
+
     steps:
       - name: Clone
         uses: actions/checkout@v6
@@ -98,6 +110,10 @@ jobs:
       matrix:
         device: [SM8750, SM8850, QCS9075M]

+    permissions:
+      actions: read
+      contents: read
+
     steps:
       - name: Checkout
         uses: actions/checkout@v6
diff --git a/.github/workflows/build-android.yml b/.github/workflows/build-android.yml
index 90960a7f6..4db7c2269 100644
--- a/.github/workflows/build-android.yml
+++ b/.github/workflows/build-android.yml
@@ -20,6 +20,10 @@ on:
       - '.github/workflows/build-android.yml'
       - 'examples/llama.android/**'

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -66,6 +70,10 @@ jobs:
       run:
         shell: bash

+    permissions:
+      actions: write
+      contents: read
+
     steps:
       - name: Clone
         uses: actions/checkout@v6
diff --git a/.github/workflows/build-apple.yml b/.github/workflows/build-apple.yml
index f87f13463..8845bfb2a 100644
--- a/.github/workflows/build-apple.yml
+++ b/.github/workflows/build-apple.yml
@@ -26,6 +26,10 @@ on:
       'ggml/src/ggml-rpc/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -50,7 +54,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: apple-arm64
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -113,7 +117,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: apple-x64
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -161,6 +165,10 @@ jobs:
   macos-latest-ios-xcode:
     runs-on: macos-latest

+    permissions:
+      actions: write
+      contents: read
+
     steps:
       - name: Checkout code
         uses: actions/checkout@v6
@@ -258,6 +266,10 @@ jobs:
     runs-on: macos-latest
     needs: macos-latest-ios-xcode

+    permissions:
+      actions: read
+      contents: read
+
     strategy:
       matrix:
         destination: ['generic/platform=macOS', 'generic/platform=iOS', 'generic/platform=tvOS']
diff --git a/.github/workflows/build-cache.yml b/.github/workflows/build-cache.yml
index 28be179d7..e5aa611e4 100644
--- a/.github/workflows/build-cache.yml
+++ b/.github/workflows/build-cache.yml
@@ -5,6 +5,10 @@ on:
   schedule:
     - cron: '0 * * * *'

+cache-mode: write
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-cann.yml b/.github/workflows/build-cann.yml
index 6d76ed499..1e5ac982b 100644
--- a/.github/workflows/build-cann.yml
+++ b/.github/workflows/build-cann.yml
@@ -22,6 +22,10 @@ on:
       'ggml/src/ggml-cann/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-cmake-pkg.yml b/.github/workflows/build-cmake-pkg.yml
index e83589282..e5be1dae1 100644
--- a/.github/workflows/build-cmake-pkg.yml
+++ b/.github/workflows/build-cmake-pkg.yml
@@ -3,6 +3,10 @@ on:
   workflow_dispatch:
   workflow_call:

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
   linux:
     runs-on: [self-hosted, Linux, CPU]
diff --git a/.github/workflows/build-cpu.yml b/.github/workflows/build-cpu.yml
index cde01952f..78d1c5f82 100644
--- a/.github/workflows/build-cpu.yml
+++ b/.github/workflows/build-cpu.yml
@@ -30,6 +30,10 @@ on:
       '**/*.cpp'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -65,7 +69,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: cpu-${{ matrix.os }}
+          restore: false
           save: false

       - name: Build Dependencies
@@ -142,6 +146,11 @@ jobs:
     name: windows / ${{ matrix.build }}
     runs-on: windows-2025

+    cache-mode: write
+    permissions:
+      actions: write
+      contents: read
+
     env:
       OPENBLAS_VERSION: 0.3.23
       SDE_VERSION: 9.33.0-2024-01-07
diff --git a/.github/workflows/build-cross.yml b/.github/workflows/build-cross.yml
index eef78b674..cc432bd4f 100644
--- a/.github/workflows/build-cross.yml
+++ b/.github/workflows/build-cross.yml
@@ -15,6 +15,10 @@ on:
   schedule:
     - cron: '0 0 * * 0'

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-cuda-ubuntu.yml b/.github/workflows/build-cuda-ubuntu.yml
index e76a2acf5..db97aeb15 100644
--- a/.github/workflows/build-cuda-ubuntu.yml
+++ b/.github/workflows/build-cuda-ubuntu.yml
@@ -24,6 +24,10 @@ on:
       'ggml/src/ggml-cuda/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -55,7 +59,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: cuda-ubuntu-24.04-cuda
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -110,7 +114,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: cuda-ubuntu-22.04-hip
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -161,7 +165,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: cuda-ubuntu-22.04-musa
+          restore: false
           save: false

       - name: ccache-buckets-restore
diff --git a/.github/workflows/build-cuda-windows.yml b/.github/workflows/build-cuda-windows.yml
index f722874bd..309f41789 100644
--- a/.github/workflows/build-cuda-windows.yml
+++ b/.github/workflows/build-cuda-windows.yml
@@ -7,6 +7,11 @@ name: CI (CUDA, windows)
 on:
   workflow_dispatch: # allows manual triggering

+cache-mode: write
+permissions:
+  actions: write
+  contents: read
+
 # note: this will run in queue with the release workflow
 concurrency:
   group: release
diff --git a/.github/workflows/build-ibm.yml b/.github/workflows/build-ibm.yml
index ac2f7df06..fcf90ccee 100644
--- a/.github/workflows/build-ibm.yml
+++ b/.github/workflows/build-ibm.yml
@@ -23,6 +23,10 @@ on:
       'ggml/src/ggml-zdnn/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-msys.yml b/.github/workflows/build-msys.yml
index 9f05a9e94..0dbf98504 100644
--- a/.github/workflows/build-msys.yml
+++ b/.github/workflows/build-msys.yml
@@ -8,6 +8,10 @@ on:
   schedule:
     - cron: '0 0 * * 0'

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-opencl.yml b/.github/workflows/build-opencl.yml
index 9be2ba1eb..ab9ed3ec2 100644
--- a/.github/workflows/build-opencl.yml
+++ b/.github/workflows/build-opencl.yml
@@ -23,6 +23,11 @@ on:
       'ggml/src/ggml-opencl/**'
     ]

+cache-mode: write
+permissions:
+  actions: write
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-openvino.yml b/.github/workflows/build-openvino.yml
index d325c368d..fdc960c23 100644
--- a/.github/workflows/build-openvino.yml
+++ b/.github/workflows/build-openvino.yml
@@ -22,6 +22,10 @@ on:
       'ggml/src/ggml-openvino/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -94,6 +98,11 @@ jobs:
   openvino-windows-2022:
     runs-on: windows-2022

+    cache-mode: write
+    permissions:
+      actions: write
+      contents: read
+
     env:
       # Sync versions in build-openvino.yml, build-self-hosted.yml, release.yml, build-cache.yml, .devops/openvino.Dockerfile
       OPENVINO_VERSION_MAJOR: "2026.4.1"
diff --git a/.github/workflows/build-riscv.yml b/.github/workflows/build-riscv.yml
index 23a64454e..b6313c777 100644
--- a/.github/workflows/build-riscv.yml
+++ b/.github/workflows/build-riscv.yml
@@ -22,6 +22,10 @@ on:
       'ggml/src/ggml-cpu/arch/riscv/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-sanitize.yml b/.github/workflows/build-sanitize.yml
index 89fcff71d..3a78c4d09 100644
--- a/.github/workflows/build-sanitize.yml
+++ b/.github/workflows/build-sanitize.yml
@@ -21,6 +21,10 @@ on:
       '.github/workflows/build-sanitize.yml'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-sycl.yml b/.github/workflows/build-sycl.yml
index ddc4e7f2b..741c9ce77 100644
--- a/.github/workflows/build-sycl.yml
+++ b/.github/workflows/build-sycl.yml
@@ -22,6 +22,10 @@ on:
       'ggml/src/ggml-sycl/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -78,7 +82,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: sycl-ubuntu-24-${{ matrix.build }}
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -124,6 +128,11 @@ jobs:
   windows-latest-sycl:
     runs-on: windows-2022

+    cache-mode: write
+    permissions:
+      actions: write
+      contents: read
+
     defaults:
       run:
         shell: bash
diff --git a/.github/workflows/build-virtgpu.yml b/.github/workflows/build-virtgpu.yml
index 5b740590d..576865783 100644
--- a/.github/workflows/build-virtgpu.yml
+++ b/.github/workflows/build-virtgpu.yml
@@ -22,6 +22,10 @@ on:
       'ggml/src/ggml-virtgpu/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/build-vulkan.yml b/.github/workflows/build-vulkan.yml
index f36227252..4ba143ef6 100644
--- a/.github/workflows/build-vulkan.yml
+++ b/.github/workflows/build-vulkan.yml
@@ -24,6 +24,10 @@ on:
       'ggml/src/ggml-vulkan/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -56,7 +60,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: vulkan-ubuntu-24.04-arm
+          restore: false
           variant: ccache
           save: false

@@ -125,7 +129,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: vulkan-ubuntu-24.04-llvmpipe
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -170,6 +174,11 @@ jobs:
   windows:
     runs-on: windows-2025

+    cache-mode: write
+    permissions:
+      actions: write
+      contents: read
+
     env:
       VULKAN_VERSION: 1.4.357.0

diff --git a/.github/workflows/build-wasm.yml b/.github/workflows/build-wasm.yml
index 5a3166ce6..f96fd85a9 100644
--- a/.github/workflows/build-wasm.yml
+++ b/.github/workflows/build-wasm.yml
@@ -33,6 +33,10 @@ on:
       'ggml/src/ggml-webgpu/wgsl-shaders/embed_wgsl.py'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -56,7 +60,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: webgpu-ubuntu-24.04-arm-wasm
+          restore: false
           save: false

       - name: Install Emscripten
diff --git a/.github/workflows/build-webgpu.yml b/.github/workflows/build-webgpu.yml
index ec582ff27..d00106439 100644
--- a/.github/workflows/build-webgpu.yml
+++ b/.github/workflows/build-webgpu.yml
@@ -25,6 +25,10 @@ on:
       'ggml/src/ggml-webgpu/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -71,7 +75,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: webgpu-macos-latest
+          restore: false
           save: false

       - name: Dawn Dependency
@@ -132,7 +136,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: webgpu-ubuntu-24.04
+          restore: false
           save: false

       - name: Dependencies
diff --git a/.github/workflows/check-vendor.yml b/.github/workflows/check-vendor.yml
index 1671ed7b8..e4c254593 100644
--- a/.github/workflows/check-vendor.yml
+++ b/.github/workflows/check-vendor.yml
@@ -17,6 +17,10 @@ on:
       'scripts/sync_vendor.py'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
   check-vendor:
     runs-on: ubuntu-slim
diff --git a/.github/workflows/ci-self-hosted-cpu.yml b/.github/workflows/ci-self-hosted-cpu.yml
index 18bc9f144..eb40baa88 100644
--- a/.github/workflows/ci-self-hosted-cpu.yml
+++ b/.github/workflows/ci-self-hosted-cpu.yml
@@ -27,6 +27,10 @@ on:
       'ggml/src/ggml-cpu/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/ci-self-hosted-cuda.yml b/.github/workflows/ci-self-hosted-cuda.yml
index 24f830a9f..89605f4dd 100644
--- a/.github/workflows/ci-self-hosted-cuda.yml
+++ b/.github/workflows/ci-self-hosted-cuda.yml
@@ -30,6 +30,10 @@ on:
       'ggml/src/ggml-cuda/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/ci-self-hosted-kleidiai.yml b/.github/workflows/ci-self-hosted-kleidiai.yml
index c955aa002..c5f5670ce 100644
--- a/.github/workflows/ci-self-hosted-kleidiai.yml
+++ b/.github/workflows/ci-self-hosted-kleidiai.yml
@@ -27,6 +27,10 @@ on:
       'ggml/src/ggml-cpu/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/ci-self-hosted-metal.yml b/.github/workflows/ci-self-hosted-metal.yml
index 7af30e294..5eb20096a 100644
--- a/.github/workflows/ci-self-hosted-metal.yml
+++ b/.github/workflows/ci-self-hosted-metal.yml
@@ -31,6 +31,10 @@ on:
       'ggml/src/ggml-metal/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/ci-self-hosted-openvino.yml b/.github/workflows/ci-self-hosted-openvino.yml
index c64c3a1a4..bf7a55bd8 100644
--- a/.github/workflows/ci-self-hosted-openvino.yml
+++ b/.github/workflows/ci-self-hosted-openvino.yml
@@ -28,6 +28,10 @@ on:
       'ggml/src/ggml-openvino/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/ci-self-hosted-vulkan.yml b/.github/workflows/ci-self-hosted-vulkan.yml
index ffed4b09b..e651f2d1d 100644
--- a/.github/workflows/ci-self-hosted-vulkan.yml
+++ b/.github/workflows/ci-self-hosted-vulkan.yml
@@ -30,6 +30,10 @@ on:
       'ggml/src/ggml-vulkan/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/ci-self-hosted-webgpu.yml b/.github/workflows/ci-self-hosted-webgpu.yml
index a6a36a8eb..316ed33b9 100644
--- a/.github/workflows/ci-self-hosted-webgpu.yml
+++ b/.github/workflows/ci-self-hosted-webgpu.yml
@@ -29,6 +29,10 @@ on:
       'ggml/src/ggml-webgpu/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/close-issue.yml b/.github/workflows/close-issue.yml
index 4698cee55..744319c26 100644
--- a/.github/workflows/close-issue.yml
+++ b/.github/workflows/close-issue.yml
@@ -3,10 +3,9 @@ on:
   schedule:
     - cron: "42 0 * * *"

-# Fine-grant permission
-# https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token
+cache-mode: none
 permissions:
-  issues: write
+  contents: read

 jobs:
   close-issues:
diff --git a/.github/workflows/code-style.yml b/.github/workflows/code-style.yml
index c88396c0a..e114d10dd 100644
--- a/.github/workflows/code-style.yml
+++ b/.github/workflows/code-style.yml
@@ -9,6 +9,10 @@ on:
     branches:
       - master

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml
index b2aafc985..1d7579cb0 100644
--- a/.github/workflows/docker.yml
+++ b/.github/workflows/docker.yml
@@ -20,15 +20,15 @@ on:
     # Rebuild daily rather than on every push because it is expensive
     - cron: '12 4 * * *'

+cache-mode: none
+permissions:
+  contents: read
+  packages: write
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true

-# Fine-grant permission
-# https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#modifying-the-permissions-for-the-github_token
-permissions:
-  packages: write
-
 jobs:
   create_tag:
     name: Create and push git tag
diff --git a/.github/workflows/editorconfig.yml b/.github/workflows/editorconfig.yml
index 53f6a0ccf..7a5a01d03 100644
--- a/.github/workflows/editorconfig.yml
+++ b/.github/workflows/editorconfig.yml
@@ -9,6 +9,10 @@ on:
     branches:
       - master

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/gguf-publish.yml b/.github/workflows/gguf-publish.yml
index 613562479..367b29c60 100644
--- a/.github/workflows/gguf-publish.yml
+++ b/.github/workflows/gguf-publish.yml
@@ -17,6 +17,9 @@ on:
     tags:
       - 'gguf-v*'           # Push events to every version tag

+cache-mode: none
+permissions:
+  contents: read

 jobs:
   deploy:
diff --git a/.github/workflows/hip-quality-check.yml b/.github/workflows/hip-quality-check.yml
index ee4e746f2..325e1ebaa 100644
--- a/.github/workflows/hip-quality-check.yml
+++ b/.github/workflows/hip-quality-check.yml
@@ -25,6 +25,10 @@ on:
       'scripts/hip/gcn-cdna-vgpr-check.py'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
@@ -54,7 +58,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: hip-quality-check-ubuntu-22.04
+          restore: false
           save: false

       - name: ccache-buckets-restore
diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml
index eab20c688..bc2c9ea45 100644
--- a/.github/workflows/labeler.yml
+++ b/.github/workflows/labeler.yml
@@ -2,6 +2,10 @@ name: "Pull Request Labeler"
 on:
 - pull_request_target

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
   labeler:
     permissions:
diff --git a/.github/workflows/make-release.yml b/.github/workflows/make-release.yml
index 101ad43f3..93df37f0e 100644
--- a/.github/workflows/make-release.yml
+++ b/.github/workflows/make-release.yml
@@ -27,6 +27,7 @@ on:
 env:
   GH_TOKEN: ${{ github.token }}

+cache-mode: none
 permissions:
   contents: write
   packages: write
diff --git a/.github/workflows/models-check.yml b/.github/workflows/models-check.yml
index 51563eace..f82e0781e 100644
--- a/.github/workflows/models-check.yml
+++ b/.github/workflows/models-check.yml
@@ -29,6 +29,10 @@ on:
       'src/models/**'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/pr-draft-label.yml b/.github/workflows/pr-draft-label.yml
index d2594c823..67a2bf3c2 100644
--- a/.github/workflows/pr-draft-label.yml
+++ b/.github/workflows/pr-draft-label.yml
@@ -4,6 +4,7 @@ on:
   pull_request_target:
     types: [labeled]

+cache-mode: none
 permissions:
   pull-requests: write
   issues: write
diff --git a/.github/workflows/pre-tokenizer-hashes.yml b/.github/workflows/pre-tokenizer-hashes.yml
index bfb79f698..0ba66ec25 100644
--- a/.github/workflows/pre-tokenizer-hashes.yml
+++ b/.github/workflows/pre-tokenizer-hashes.yml
@@ -10,6 +10,10 @@ on:
             - 'conversion/base.py'
             - 'convert_hf_to_gguf_update.py'

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
     pre-tokenizer-hashes:
         runs-on: ubuntu-slim
diff --git a/.github/workflows/python-check-requirements.yml b/.github/workflows/python-check-requirements.yml
index e21c7da57..9738ff778 100644
--- a/.github/workflows/python-check-requirements.yml
+++ b/.github/workflows/python-check-requirements.yml
@@ -14,6 +14,10 @@ on:
       - 'convert*.py'
       - '**/requirements*.txt'

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/python-lint.yml b/.github/workflows/python-lint.yml
index 1e5d64c1a..f2d284af5 100644
--- a/.github/workflows/python-lint.yml
+++ b/.github/workflows/python-lint.yml
@@ -15,6 +15,10 @@ on:
       '**/*.py'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/python-type-check.yml b/.github/workflows/python-type-check.yml
index 7a2b65890..5be177e9c 100644
--- a/.github/workflows/python-type-check.yml
+++ b/.github/workflows/python-type-check.yml
@@ -16,6 +16,10 @@ on:
       - '**/requirements*.txt'
       # - 'pyrightconfig.json'

+cache-mode: none
+permissions:
+  contents: read
+
 concurrency:
   group: ${{ github.workflow }}-${{ github.head_ref && github.ref || github.run_id }}
   cancel-in-progress: true
diff --git a/.github/workflows/release-publish.yml b/.github/workflows/release-publish.yml
index f6219dba5..31fb1481a 100644
--- a/.github/workflows/release-publish.yml
+++ b/.github/workflows/release-publish.yml
@@ -9,6 +9,11 @@ on:
     branches:
       - master

+cache-mode: none
+permissions:
+  actions: read
+  contents: read
+
 env:
   GH_TOKEN: ${{ github.token }}
   BRANCH_NAME: master
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 4d714f421..c826de1fd 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -27,6 +27,11 @@ on:
       '**/*.glsl'
     ]

+cache-mode: write
+permissions:
+  actions: write
+  contents: read
+
 env:
   GH_TOKEN: ${{ github.token }}
   BRANCH_NAME: ${{ github.head_ref || github.ref_name }}
@@ -114,9 +119,6 @@ jobs:

     runs-on: ${{ matrix.os }}

-    permissions:
-      actions: write
-
     steps:
       - name: Clone
         id: checkout
@@ -181,9 +183,6 @@ jobs:

     runs-on: ${{ matrix.os }}

-    permissions:
-      actions: write
-
     steps:
       - name: Clone
         id: checkout
@@ -262,9 +261,6 @@ jobs:

     runs-on: ${{ matrix.os }}

-    permissions:
-      actions: write
-
     steps:
       - name: Clone
         id: checkout
@@ -359,9 +355,6 @@ jobs:
     runs-on: ${{ matrix.os }}
     container: nvidia/cuda:${{ matrix.cuda }}-devel-ubuntu24.04

-    permissions:
-      actions: write
-
     steps:
       # the container has no git; install it before checkout so that a real git repository is created
       - name: Install git
@@ -470,9 +463,6 @@ jobs:

     runs-on: ubuntu-24.04  # previously ubuntu-latest

-    permissions:
-      actions: write
-
     env:
       NDK_VERSION: "29.0.14206865"

@@ -559,9 +549,6 @@ jobs:
     runs-on: ubuntu-latest
     container: 'ghcr.io/snapdragon-toolchain/arm64-android:v0.7'

-    permissions:
-      actions: write
-
     defaults:
       run:
         shell: bash
@@ -615,9 +602,6 @@ jobs:
     runs-on: ubuntu-latest
     container: 'ghcr.io/snapdragon-toolchain/arm64-linux:v0.7'

-    permissions:
-      actions: write
-
     defaults:
       run:
         shell: bash
@@ -670,9 +654,6 @@ jobs:

     runs-on: ubuntu-24.04

-    permissions:
-      actions: write
-
     outputs:
       openvino_version: ${{ steps.openvino_version.outputs.value }}

@@ -784,9 +765,6 @@ jobs:

     runs-on: windows-2022

-    permissions:
-      actions: write
-
     outputs:
       openvino_version: ${{ steps.openvino_version.outputs.value }}

@@ -912,9 +890,6 @@ jobs:

     runs-on: windows-2025-vs2026

-    permissions:
-      actions: write
-
     strategy:
       matrix:
         include:
@@ -982,9 +957,6 @@ jobs:

     runs-on: windows-2022

-    permissions:
-      actions: write
-
     strategy:
       matrix:
         include:
@@ -1142,9 +1114,6 @@ jobs:

     runs-on: windows-2025

-    permissions:
-      actions: write
-
     env:
       OPENBLAS_VERSION: 0.3.23
       VULKAN_VERSION: 1.4.357.0
@@ -1238,9 +1207,6 @@ jobs:

     runs-on: windows-2022

-    permissions:
-      actions: write
-
     strategy:
       matrix:
         include:
@@ -1339,9 +1305,6 @@ jobs:

     runs-on: windows-2022

-    permissions:
-      actions: write
-
     defaults:
       run:
         shell: bash
@@ -1455,9 +1418,6 @@ jobs:

     runs-on: ubuntu-24.04

-    permissions:
-      actions: write
-
     env:
       ONEAPI_ROOT: /opt/intel/oneapi/
       ONEAPI_INSTALLER_VERSION: "2026.1"
@@ -1538,9 +1498,6 @@ jobs:

     runs-on: ubuntu-24.04

-    permissions:
-      actions: write
-
     strategy:
       matrix:
         include:
@@ -1660,9 +1617,6 @@ jobs:
     if: ${{ needs.check-release.outputs.should_release == 'true' }}
     runs-on: macos-26

-    permissions:
-      actions: write
-
     steps:
       - name: Checkout code
         uses: actions/checkout@v6
@@ -1738,8 +1692,6 @@ jobs:
 #            build: 'Release'
 #            use_acl_graph: 'off'
 #    runs-on: ${{ matrix.arch == 'aarch64' && 'ubuntu-24.04-arm' || 'ubuntu-24.04' }}
-#    permissions:
-#      actions: write
 #    steps:
 #      - name: Checkout
 #        uses: actions/checkout@v6
diff --git a/.github/workflows/server-sanitize.yml b/.github/workflows/server-sanitize.yml
index 69777b6a2..4202c31e7 100644
--- a/.github/workflows/server-sanitize.yml
+++ b/.github/workflows/server-sanitize.yml
@@ -31,6 +31,10 @@ on:
       '.github/workflows/server-sanitize.yml'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 env:
   # note: this is dud token to avoid rate limiting (https://github.com/ggml-org/llama.cpp/pull/25706#issuecomment-4979941302)
   HF_TOKEN: ${{ secrets.HF_TOKEN_CI }}
diff --git a/.github/workflows/server-self-hosted.yml b/.github/workflows/server-self-hosted.yml
index 614fd32f5..c5dd86449 100644
--- a/.github/workflows/server-self-hosted.yml
+++ b/.github/workflows/server-self-hosted.yml
@@ -28,6 +28,10 @@ on:
       'tools/server/**.*'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 env:
   # note: this is dud token to avoid rate limiting (https://github.com/ggml-org/llama.cpp/pull/25706#issuecomment-4979941302)
   HF_TOKEN: ${{ secrets.HF_TOKEN_CI }}
diff --git a/.github/workflows/server.yml b/.github/workflows/server.yml
index 77fe7dbd3..05dd0ac45 100644
--- a/.github/workflows/server.yml
+++ b/.github/workflows/server.yml
@@ -43,6 +43,10 @@ on:
       'tools/server/**.*'
     ]

+cache-mode: none
+permissions:
+  contents: read
+
 env:
   LLAMA_ARG_LOG_COLORS: 1
   LLAMA_ARG_LOG_PREFIX: 1
@@ -82,7 +86,7 @@ jobs:
       - name: ccache
         uses: ggml-org/ccache-action@v1.2.24
         with:
-          key: server-ubuntu-24.04-arm
+          restore: false
           save: false

       - name: ccache-buckets-restore
@@ -151,6 +155,11 @@ jobs:
   windows:
     runs-on: windows-2025

+    cache-mode: write
+    permissions:
+      actions: write
+      contents: read
+
     steps:
       - name: Clone
         id: checkout
diff --git a/.github/workflows/ui-build-self-hosted.yml b/.github/workflows/ui-build-self-hosted.yml
index e93a89003..0ba2eb983 100644
--- a/.github/workflows/ui-build-self-hosted.yml
+++ b/.github/workflows/ui-build-self-hosted.yml
@@ -3,6 +3,11 @@ name: UI Build (self-hosted)
 on:
   workflow_call:

+cache-mode: none
+permissions:
+  actions: write
+  contents: read
+
 jobs:
   build:
     runs-on: [self-hosted, fast]
diff --git a/.github/workflows/ui-build.yml b/.github/workflows/ui-build.yml
index 4da505959..e0d8dd065 100644
--- a/.github/workflows/ui-build.yml
+++ b/.github/workflows/ui-build.yml
@@ -8,14 +8,15 @@ on:
         required: false
         type: string

+cache-mode: none
+permissions:
+  actions: write
+  contents: read
+
 jobs:
   build:
     runs-on: ubuntu-slim

-    permissions:
-      actions: write
-      contents: read
-
     steps:
       - name: Checkout code
         uses: actions/checkout@v6
diff --git a/.github/workflows/ui-publish.yml b/.github/workflows/ui-publish.yml
index a1fb93ed3..d77b899b2 100644
--- a/.github/workflows/ui-publish.yml
+++ b/.github/workflows/ui-publish.yml
@@ -15,15 +15,16 @@ on:
         description: 'Hugging Face token with write access'
         required: true

+cache-mode: none
+permissions:
+  actions: read
+  contents: read
+
 jobs:
   publish:
     name: Publish UI Static Output
     runs-on: ubuntu-slim

-    permissions:
-      actions: read
-      contents: read
-
     env:
       HF_BUCKET_NAME: ${{ vars.HF_BUCKET_UI_STATIC_OUTPUT }}

diff --git a/.github/workflows/ui-self-hosted.yml b/.github/workflows/ui-self-hosted.yml
index 63521ead2..93b7805f1 100644
--- a/.github/workflows/ui-self-hosted.yml
+++ b/.github/workflows/ui-self-hosted.yml
@@ -29,6 +29,11 @@ on:
       'tools/server/tests/**.*'
     ]

+cache-mode: none
+permissions:
+  actions: read
+  contents: read
+
 env:
   LLAMA_ARG_LOG_COLORS: 1
   LLAMA_ARG_LOG_PREFIX: 1
@@ -43,6 +48,9 @@ jobs:
   ui-build:
     name: Build static output
     uses: ./.github/workflows/ui-build-self-hosted.yml
+    permissions:
+      actions: write
+      contents: read

   ui-checks:
     name: Checks
diff --git a/.github/workflows/ui.yml b/.github/workflows/ui.yml
index f395c0b52..c5c6a32a8 100644
--- a/.github/workflows/ui.yml
+++ b/.github/workflows/ui.yml
@@ -25,6 +25,11 @@ on:
       'tools/server/tests/**.*'
     ]

+cache-mode: none
+permissions:
+  actions: read
+  contents: read
+
 env:
   LLAMA_ARG_LOG_COLORS: 1
   LLAMA_ARG_LOG_PREFIX: 1
@@ -39,6 +44,9 @@ jobs:
   ui-build:
     name: Build static output
     uses: ./.github/workflows/ui-build.yml
+    permissions:
+      actions: write
+      contents: read

   ui-checks:
     name: Checks
diff --git a/.github/workflows/update-ops-docs.yml b/.github/workflows/update-ops-docs.yml
index bb01c7e56..c94fd8500 100644
--- a/.github/workflows/update-ops-docs.yml
+++ b/.github/workflows/update-ops-docs.yml
@@ -14,6 +14,10 @@ on:
             - 'docs/ops/**'
             - 'scripts/create_ops_docs.py'

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
     update-ops-docs:
         runs-on: ubuntu-slim
diff --git a/.github/workflows/winget.yml b/.github/workflows/winget.yml
index 7af2e9b10..1abaaf94b 100644
--- a/.github/workflows/winget.yml
+++ b/.github/workflows/winget.yml
@@ -5,6 +5,10 @@ on:
   schedule:
     - cron: '28 5 * * *' # Update every day at 5:28 UTC

+cache-mode: none
+permissions:
+  contents: read
+
 jobs:
   update:
     name: Update Winget Package