Skip to content

Commit 233dfc4

Browse files
committed
No issue - restrict token-permissions in ci.yaml
1 parent 7e01884 commit 233dfc4

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

.github/workflows/ci.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,7 @@
11
name: Docker
22

3+
permissions: read-all
4+
35
on:
46
push:
57
branches:
@@ -16,6 +18,8 @@ jobs:
1618

1719
tests:
1820
runs-on: ubuntu-latest
21+
permissions:
22+
security-events: write
1923
steps:
2024
- uses: actions/checkout@v4
2125

@@ -99,6 +103,9 @@ jobs:
99103

100104
security-scan:
101105
runs-on: ubuntu-latest
106+
permissions:
107+
security-events: write
108+
102109
steps:
103110
- uses: actions/checkout@v4
104111

@@ -225,6 +232,9 @@ jobs:
225232
- integration-test
226233
- security-scan
227234
runs-on: ubuntu-latest
235+
permissions:
236+
contents: write
237+
packages: write
228238
steps:
229239
- uses: actions/checkout@v4
230240

0 commit comments

Comments
 (0)