From 847917c1e253edb6438b085373f0b8aeab0fa20f Mon Sep 17 00:00:00 2001 From: Alex Date: Thu, 8 Dec 2022 20:33:54 +0200 Subject: [PATCH 1/2] build: harden dependencies.yml permissions Signed-off-by: Alex --- .github/workflows/dependencies.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/dependencies.yml b/.github/workflows/dependencies.yml index 0a53c97dcc..add695b41a 100644 --- a/.github/workflows/dependencies.yml +++ b/.github/workflows/dependencies.yml @@ -5,6 +5,10 @@ on: branches: [ "main" ] pull_request: branches: [ "main" ] + +permissions: + contents: read # to fetch code (actions/checkout) + jobs: build: runs-on: ubuntu-latest From 724ff4eeebbf7778a94e182ab0084491808d22ad Mon Sep 17 00:00:00 2001 From: Bailey Pearson Date: Tue, 13 Dec 2022 13:23:28 -0500 Subject: [PATCH 2/2] Update .github/workflows/dependencies.yml --- .github/workflows/dependencies.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/dependencies.yml b/.github/workflows/dependencies.yml index add695b41a..40356a5cdf 100644 --- a/.github/workflows/dependencies.yml +++ b/.github/workflows/dependencies.yml @@ -7,7 +7,7 @@ on: branches: [ "main" ] permissions: - contents: read # to fetch code (actions/checkout) + contents: read jobs: build: