Skip to content

Commit caa2f78

Browse files
authored
limit PR permissions (#2077)
1 parent 72ea185 commit caa2f78

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

.github/workflows/cpu-tests.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,20 @@ on:
99
pull_request: {} # todo
1010
workflow_dispatch: {}
1111

12+
# lock down all permissions by default
13+
permissions:
14+
contents: read
15+
issues: read
16+
pull-requests: read
17+
id-token: read
18+
security-events: read
19+
actions: read
20+
checks: write
21+
deployments: read
22+
discussions: read
23+
packages: read
24+
statuses: write
25+
1226
concurrency:
1327
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.head_ref }}
1428
cancel-in-progress: ${{ github.event_name == 'pull_request_target' }}

0 commit comments

Comments
 (0)