瀏覽代碼

Update security permissions for GitHub workflows (#252)

Andrew Tan 2 年之前
父節點
當前提交
f1bc157d69
共有 3 個文件被更改,包括 9 次插入0 次删除
  1. 2 0
      .github/workflows/build-publish.yml
  2. 3 0
      .github/workflows/build.yml
  3. 4 0
      .github/workflows/pre-commit.yml

+ 2 - 0
.github/workflows/build-publish.yml

@@ -18,6 +18,8 @@ on:
 jobs:
   build-wheels:
     runs-on: ubuntu-latest
+    permissions:
+      contents: read
     steps:
       - uses: actions/checkout@v3
       - name: Set up Python

+ 3 - 0
.github/workflows/build.yml

@@ -1,6 +1,9 @@
 name: build
 on: [pull_request, push]
 
+permissions:
+  contents: read
+
 jobs:
   build:
     runs-on: ubuntu-latest

+ 4 - 0
.github/workflows/pre-commit.yml

@@ -2,6 +2,10 @@
 # This GitHub Action assumes that the repo contains a valid .pre-commit-config.yaml file.
 name: pre-commit
 on: [pull_request, push]
+
+permissions:
+  contents: read
+
 jobs:
   pre-commit:
     runs-on: ubuntu-latest