Skip to content

Commit 5cb9723

Browse files
authored
Harden GitHub Actions: set explicit permissions (#40)
1 parent 7bda9c0 commit 5cb9723

2 files changed

Lines changed: 7 additions & 0 deletions

File tree

.github/workflows/add-issue-to-project.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,9 @@ on:
44
issues:
55
types: [opened]
66

7+
permissions:
8+
contents: read
9+
710
jobs:
811
add-to-project:
912
uses: turbot/steampipe-workflows/.github/workflows/assign-issue-to-project.yml@main

.github/workflows/registry-publish.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ on:
55
tags:
66
- 'v*'
77

8+
permissions:
9+
contents: read
10+
packages: write
11+
812
jobs:
913
registry_publish_workflow_ghcr:
1014
uses: turbot/steampipe-workflows/.github/workflows/registry-publish-ghcr.yml@main

0 commit comments

Comments
 (0)