Skip to content

Commit b62c434

Browse files
authored
fix(scorecard): don't declare any permissions at top-level (#85)
1 parent 9f3c83a commit b62c434

1 file changed

Lines changed: 9 additions & 7 deletions

File tree

.github/workflows/scorecard.yml

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -16,19 +16,21 @@ on:
1616
- main
1717
workflow_call:
1818

19-
permissions:
20-
# Needed to upload the results to code-scanning dashboard.
21-
security-events: write
22-
# Needed to publish results and get a badge (see publish_results below).
23-
id-token: write
24-
contents: read
25-
actions: read
19+
permissions: {}
2620

2721
jobs:
2822
analysis:
2923
name: Scorecard analysis
3024
runs-on: ubuntu-latest
3125

26+
permissions:
27+
# Needed to upload the results to code-scanning dashboard.
28+
security-events: write
29+
# Needed to publish results and get a badge (see publish_results below).
30+
id-token: write
31+
contents: read
32+
actions: read
33+
3234
steps:
3335
- name: Harden Runner
3436
uses: step-security/harden-runner@f4a75cfd619ee5ce8d5b864b0d183aff3c69b55a # v2.13.1

0 commit comments

Comments
 (0)