Skip to content

Commit e9caf43

Browse files
committed
Fix zizmor findings
1 parent f352ae8 commit e9caf43

File tree

2 files changed

+13
-2
lines changed

2 files changed

+13
-2
lines changed

.github/workflows/ci.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ on:
66
push:
77
branches: [main]
88

9+
permissions: {}
10+
911
concurrency:
1012
group: ci-${{ github.ref }}
1113
cancel-in-progress: true
@@ -17,6 +19,8 @@ jobs:
1719
steps:
1820
- name: Checkout
1921
uses: actions/checkout@v6
22+
with:
23+
persist-credentials: false
2024

2125
- name: Setup Bun
2226
uses: oven-sh/setup-bun@v2
@@ -38,6 +42,8 @@ jobs:
3842
steps:
3943
- name: Checkout
4044
uses: actions/checkout@v6
45+
with:
46+
persist-credentials: false
4147

4248
- name: Spell check
4349
uses: crate-ci/typos@v1.44.0
@@ -49,6 +55,8 @@ jobs:
4955
steps:
5056
- name: Checkout
5157
uses: actions/checkout@v6
58+
with:
59+
persist-credentials: false
5260

5361
- name: Setup Bun
5462
uses: oven-sh/setup-bun@v2

.github/workflows/deploy.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,6 @@ on:
77

88
permissions:
99
contents: read
10-
pages: write
11-
id-token: write
1210

1311
concurrency:
1412
group: pages
@@ -21,6 +19,8 @@ jobs:
2119
steps:
2220
- name: Checkout
2321
uses: actions/checkout@v6
22+
with:
23+
persist-credentials: false
2424

2525
- name: Setup Bun
2626
uses: oven-sh/setup-bun@v2
@@ -54,6 +54,9 @@ jobs:
5454
name: Deploy
5555
runs-on: ubuntu-latest
5656
needs: build
57+
permissions:
58+
pages: write
59+
id-token: write
5760
environment:
5861
name: github-pages
5962
url: ${{ steps.deployment.outputs.page_url }}

0 commit comments

Comments
 (0)