From d42b7a1b108badf09e0227b40dedc2f25848be19 Mon Sep 17 00:00:00 2001 From: Abhinav Gupta Date: Mon, 20 Mar 2023 05:40:59 -0700 Subject: [PATCH] ci: Minimize permissions to workflows (#77) Reduces the permissions available to GitHub Workflows to read-only since they don't do much otherwise. Resolves #76 --- .github/workflows/fossa.yaml | 3 +++ .github/workflows/go.yml | 3 +++ 2 files changed, 6 insertions(+) diff --git a/.github/workflows/fossa.yaml b/.github/workflows/fossa.yaml index 86e6db7..01f3c67 100644 --- a/.github/workflows/fossa.yaml +++ b/.github/workflows/fossa.yaml @@ -1,6 +1,9 @@ name: FOSSA Analysis on: push +permissions: + contents: read + jobs: build: diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 23c78ab..2798326 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -7,6 +7,9 @@ on: pull_request: branches: ['*'] +permissions: + contents: read + jobs: build: