소스 검색

Update security permissions for GitHub workflows (#252)

Andrew Tan 2 년 전
부모
커밋
f1bc157d69
3개의 변경된 파일9개의 추가작업 그리고 0개의 파일을 삭제
  1. 2 0
      .github/workflows/build-publish.yml
  2. 3 0
      .github/workflows/build.yml
  3. 4 0
      .github/workflows/pre-commit.yml

+ 2 - 0
.github/workflows/build-publish.yml

@@ -18,6 +18,8 @@ on:
 jobs:
   build-wheels:
     runs-on: ubuntu-latest
+    permissions:
+      contents: read
     steps:
       - uses: actions/checkout@v3
       - name: Set up Python

+ 3 - 0
.github/workflows/build.yml

@@ -1,6 +1,9 @@
 name: build
 on: [pull_request, push]
 
+permissions:
+  contents: read
+
 jobs:
   build:
     runs-on: ubuntu-latest

+ 4 - 0
.github/workflows/pre-commit.yml

@@ -2,6 +2,10 @@
 # This GitHub Action assumes that the repo contains a valid .pre-commit-config.yaml file.
 name: pre-commit
 on: [pull_request, push]
+
+permissions:
+  contents: read
+
 jobs:
   pre-commit:
     runs-on: ubuntu-latest