Skip to content

Commit 9ed1a59

Browse files
committed
Workflow permissions per Scorecard recommendations
1 parent d6d4d28 commit 9ed1a59

2 files changed

Lines changed: 7 additions & 3 deletions

File tree

.github/workflows/release.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,13 +8,15 @@ on:
88
- v*.*.*
99

1010
permissions:
11-
contents: write
11+
contents: read
1212

1313
concurrency:
1414
group: release
1515

1616
jobs:
1717
create-release:
18+
permissions:
19+
contents: write
1820
runs-on: ubuntu-latest
1921
steps:
2022
- name: Clone the repository

.github/workflows/versioning.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,14 +9,16 @@ on:
99
- edited
1010

1111
permissions:
12-
contents: write
13-
pull-requests: write
12+
contents: read
1413

1514
concurrency:
1615
group: versioning
1716

1817
jobs:
1918
actions-tagger:
19+
permissions:
20+
contents: write
21+
pull-requests: write
2022
runs-on: ubuntu-latest
2123
steps:
2224
- uses: Actions-R-Us/actions-tagger@330ddfac760021349fef7ff62b372f2f691c20fb # v2.0.3

0 commit comments

Comments
 (0)