Skip to content

Commit

Permalink
build: harden workflow permissions
Browse files Browse the repository at this point in the history
Signed-off-by: Alex <[email protected]>
  • Loading branch information
sashashura authored and eli-schwartz committed Dec 1, 2022
1 parent fae24d8 commit 9074ad9
Show file tree
Hide file tree
Showing 3 changed files with 9 additions and 0 deletions.
3 changes: 3 additions & 0 deletions .github/workflows/cygwin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@ on:
- ".github/workflows/cygwin.yml"
- "run*tests.py"

permissions:
contents: read

jobs:
test:
runs-on: windows-latest
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,9 @@ on:
schedule:
- cron: '0 0 * * 0'

permissions:
contents: read

jobs:
build:
# do not run the weekly scheduled job in a fork
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/website.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@ on:
types:
- published

permissions:
contents: write # for release creation (svenstaro/upload-release-action)

# This job is copy/paster into wrapdb CI, please update it there when doing any
# change here.
jobs:
Expand Down

0 comments on commit 9074ad9

Please sign in to comment.