Make Github workflows permissions read-only by default (#3488)

* Make Github workflows permissions read-only by default

* Pins `skx/github-action-publish-binaries` action to specific hash
This commit is contained in:
Yonatan Komornik 2023-02-13 16:57:05 -08:00 committed by GitHub
parent 886de7bc04
commit 727d03161f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 6 additions and 3 deletions

View File

@ -9,6 +9,8 @@ on:
pull_request:
branches: [ dev, release, actionsTest ]
permissions: read-all
jobs:
make-all:
runs-on: ubuntu-latest

View File

@ -10,6 +10,8 @@ on:
pull_request:
branches: [ dev, release, actionsTest ]
permissions: read-all
jobs:
linux-kernel:
runs-on: ubuntu-latest

View File

@ -5,8 +5,7 @@ on:
types:
- published
permissions:
contents: read
permissions: read-all
jobs:
publish-release-artifacts:
@ -68,7 +67,7 @@ jobs:
fi
- name: Publish
uses: skx/github-action-publish-binaries@release-2.0
uses: skx/github-action-publish-binaries@b9ca5643b2f1d7371a6cba7f35333f1461bbc703 # tag=release-2.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with: