Skip to content

Commit df01136

Browse files
committed
Set per-job GitHub Actions permissions and Remove top-level permissions
1 parent 25547df commit df01136

1 file changed

Lines changed: 10 additions & 3 deletions

File tree

.github/workflows/ci.yml

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,9 +5,6 @@ on:
55
push:
66
branches:
77
- main
8-
permissions:
9-
checks: write
10-
contents: write
118
concurrency:
129
group: ${{ github.workflow }}-${{ github.ref_name }}
1310
cancel-in-progress: true
@@ -17,6 +14,10 @@ jobs:
1714
runs-on: ubuntu-latest
1815
environment:
1916
name: code_quality
17+
permissions:
18+
checks: write
19+
contents: read
20+
pull-requests: write
2021
steps:
2122
- name: Harden the runner (Audit all outbound calls)
2223
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
@@ -39,6 +40,10 @@ jobs:
3940
runs-on: ubuntu-latest
4041
environment:
4142
name: code_quality
43+
permissions:
44+
checks: write
45+
contents: write
46+
pull-requests: write
4247
steps:
4348
- name: Harden the runner (Audit all outbound calls)
4449
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0
@@ -70,6 +75,8 @@ jobs:
7075
needs: [compatibility, test]
7176
environment:
7277
name: build
78+
permissions:
79+
contents: write
7380
steps:
7481
- name: Harden the runner (Audit all outbound calls)
7582
uses: step-security/harden-runner@20cf305ff2072d973412fa9b1e3a4f227bda3c76 # v2.14.0

0 commit comments

Comments
 (0)