From c2b9039d019bae10db53c2b9560091e01ba98902 Mon Sep 17 00:00:00 2001 From: Fabio Niephaus Date: Fri, 5 Aug 2022 10:19:50 +0200 Subject: [PATCH] Set permissions for workflows. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions --- .github/workflows/check-dist.yml | 2 ++ .github/workflows/test.yml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/.github/workflows/check-dist.yml b/.github/workflows/check-dist.yml index 7a614f5..f463321 100644 --- a/.github/workflows/check-dist.yml +++ b/.github/workflows/check-dist.yml @@ -16,6 +16,8 @@ on: paths-ignore: - '**.md' workflow_dispatch: +permissions: + contents: read jobs: check-dist: diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 7469e80..51d0908 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -8,6 +8,8 @@ on: paths-ignore: - '**.md' workflow_dispatch: +permissions: + contents: read jobs: build: # make sure build/ci work properly