Skip to content

Commit eb46b7d

Browse files
authored
github: set top-level read-only workflow permissions (#6775)
1 parent be1d1c1 commit eb46b7d

File tree

5 files changed

+19
-5
lines changed

5 files changed

+19
-5
lines changed

.github/workflows/codeql-analysis.yml

+5-3
Original file line numberDiff line numberDiff line change
@@ -8,16 +8,18 @@ on:
88

99
permissions:
1010
contents: read
11-
security-events: write
12-
pull-requests: read
13-
actions: read
1411

1512
jobs:
1613
analyze:
1714
name: Analyze
1815
runs-on: ubuntu-latest
1916
timeout-minutes: 30
2017

18+
permissions:
19+
security-events: write
20+
pull-requests: read
21+
actions: read
22+
2123
strategy:
2224
fail-fast: false
2325

.github/workflows/coverage.yml

+4
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
name: codecov
22
on: [push, pull_request]
3+
4+
permissions:
5+
contents: read
6+
37
jobs:
48
upload:
59
runs-on: ubuntu-latest

.github/workflows/lock.yml

+4-2
Original file line numberDiff line numberDiff line change
@@ -6,12 +6,14 @@ on:
66
- cron: '22 1 * * *'
77

88
permissions:
9-
issues: write
10-
pull-requests: write
9+
contents: read
1110

1211
jobs:
1312
lock:
1413
runs-on: ubuntu-latest
14+
permissions:
15+
issues: write
16+
pull-requests: write
1517
steps:
1618
- uses: dessant/lock-threads@v2
1719
with:

.github/workflows/release.yml

+3
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,9 @@ on:
44
release:
55
types: [published]
66

7+
permissions:
8+
contents: read
9+
710
jobs:
811
release:
912
permissions:

.github/workflows/stale.yml

+3
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,9 @@ on:
55
schedule:
66
- cron: "44 */2 * * *"
77

8+
permissions:
9+
contents: read
10+
811
jobs:
912
stale:
1013
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)