Skip to content

Commit c3a0dd9

Browse files
authored
rescope permissions (#69)
1 parent fd1783f commit c3a0dd9

File tree

2 files changed

+17
-5
lines changed

2 files changed

+17
-5
lines changed

.github/workflows/ci.yml

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
11
name: CI
22

3-
permissions:
4-
contents: read
3+
permissions: {}
54

65
on:
76
push:
@@ -20,6 +19,8 @@ jobs:
2019
name: test ${{ matrix.rust }} ${{ matrix.flags }}
2120
runs-on: ubuntu-latest
2221
timeout-minutes: 30
22+
permissions:
23+
contents: read
2324
strategy:
2425
fail-fast: false
2526
matrix:
@@ -52,6 +53,8 @@ jobs:
5253
doctest:
5354
runs-on: ubuntu-latest
5455
timeout-minutes: 30
56+
permissions:
57+
contents: read
5558
steps:
5659
- uses: actions/checkout@v5
5760
with:
@@ -68,6 +71,8 @@ jobs:
6871
feature-checks:
6972
runs-on: ubuntu-latest
7073
timeout-minutes: 30
74+
permissions:
75+
contents: read
7176
steps:
7277
- uses: actions/checkout@v5
7378
with:
@@ -87,6 +92,8 @@ jobs:
8792
clippy:
8893
runs-on: ubuntu-latest
8994
timeout-minutes: 30
95+
permissions:
96+
contents: read
9097
steps:
9198
- uses: actions/checkout@v5
9299
with:
@@ -105,6 +112,8 @@ jobs:
105112
docs:
106113
runs-on: ubuntu-latest
107114
timeout-minutes: 30
115+
permissions:
116+
contents: read
108117
steps:
109118
- uses: actions/checkout@v5
110119
with:
@@ -122,6 +131,8 @@ jobs:
122131
fmt:
123132
runs-on: ubuntu-latest
124133
timeout-minutes: 30
134+
permissions:
135+
contents: read
125136
steps:
126137
- uses: actions/checkout@v5
127138
with:
@@ -134,11 +145,12 @@ jobs:
134145

135146
deny:
136147
uses: ithacaxyz/ci/.github/workflows/deny.yml@9c8d0dc20e7ad02455d3fdab2378a05f29907630 # main
148+
permissions:
149+
contents: read
137150

138151
ci-success:
139152
runs-on: ubuntu-latest
140153
if: always()
141-
permissions: {}
142154
needs:
143155
- test
144156
- doctest

.github/workflows/codeql.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
11
name: CodeQL
22

3-
permissions:
4-
contents: read
3+
permissions: {}
54

65
on:
76
push:
@@ -23,6 +22,7 @@ jobs:
2322
permissions:
2423
security-events: write
2524
actions: read
25+
contents: read
2626

2727
strategy:
2828
fail-fast: false

0 commit comments

Comments
 (0)