Skip to content

Commit d8d5237

Browse files
committed
fix(ci): harden GitHub Actions workflow permissions
1 parent e731131 commit d8d5237

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

.github/workflows/security-dependencies-check.yml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,15 +13,14 @@ on:
1313
name: Verify Dependencies
1414
run-name: Verify Dependencies – ${{ github.event_name }}
1515

16-
permissions:
17-
contents: read
16+
permissions: {}
1817

1918
jobs:
2019
verify:
2120
runs-on: ubuntu-latest
2221
permissions:
23-
contents: read
24-
pull-requests: write
22+
contents: read # checkout repository and read dependency snapshots
23+
pull-requests: write # post review comments
2524
steps:
2625
- name: Checkout Repository
2726
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

0 commit comments

Comments
 (0)