Skip to content

Commit 08b5a55

Browse files
committed
CI: Restrict default permissions
Reduces risk of arbitrary code is run by attacker.
1 parent 1328b1c commit 08b5a55

File tree

1 file changed

+6
-3
lines changed

1 file changed

+6
-3
lines changed

.github/workflows/main.yaml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,21 @@
11
name: CI
2-
permissions:
3-
contents: write
4-
52
on: [push, pull_request]
63

74
jobs:
85
pre-commit:
6+
permissions:
7+
contents: read
8+
99
runs-on: ubuntu-20.04
1010
steps:
1111
- uses: actions/checkout@v4
1212
- uses: actions/setup-python@v5
1313
- uses: pre-commit/action@v3.0.1
1414
build:
1515
runs-on: ubuntu-20.04
16+
permissions:
17+
contents: write
18+
1619
steps:
1720
- uses: actions/checkout@v4
1821
- uses: actions/setup-python@v5

0 commit comments

Comments
 (0)