ci: Security hardening for GitHub Actions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

The idea is that the software supply chain relies on 3rd party actions
that could be compromised. Mitigate this risk by giving these actions
minimal rights to the repository. Here read-only access is good enough.
pull/500/head
Dimitri Papadopoulos 3 years ago
parent b8c85f0dfd
commit 5dbc4e0a42
No known key found for this signature in database
GPG Key ID: 95998121D9D25F5D

@ -8,6 +8,9 @@ on: # yamllint disable-line rule:truthy
branches:
- master
permissions:
contents: read
jobs:
lint:
name: Linters

Loading…
Cancel
Save