File tree Expand file tree Collapse file tree 5 files changed +17
-8
lines changed
Expand file tree Collapse file tree 5 files changed +17
-8
lines changed Original file line number Diff line number Diff line change 2020 schedule :
2121 - cron : ' 43 21 * * 6'
2222
23- permissions :
24- contents : read
23+ # Declare default permissions as read only.
24+ permissions : read-all
2525
2626concurrency :
2727 group : codeql-${{ github.ref }}
Original file line number Diff line number Diff line change 99name : ' Dependency Review'
1010on : [pull_request]
1111
12- permissions :
13- contents : write
12+ # Declare default permissions as read only.
13+ permissions : read-all
1414
1515concurrency :
1616 group : dependency-review-${{ github.ref }}
Original file line number Diff line number Diff line change 2424 pull_request :
2525 branches : [s3mock-v2, main]
2626
27- permissions :
28- contents : read
27+ # Declare default permissions as read only.
28+ permissions : read-all
2929
3030concurrency :
3131 group : ci-${{ github.ref }}
@@ -34,7 +34,8 @@ concurrency:
3434jobs :
3535 build :
3636 runs-on : ubuntu-latest
37-
37+ permissions :
38+ contents : write
3839 steps :
3940 - name : Harden Runner
4041 uses : step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
Original file line number Diff line number Diff line change 1919name : Maven Release
2020
2121on : workflow_dispatch
22+
23+ # Declare default permissions as read only.
24+ permissions : read-all
25+
2226jobs :
2327 build :
2428 runs-on : ubuntu-latest
25-
29+ permissions :
30+ contents : write
2631 steps :
2732 - name : Harden Runner
2833 uses : step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
Original file line number Diff line number Diff line change @@ -8,6 +8,9 @@ concurrency:
88 group : sbom-${{ github.ref }}
99 cancel-in-progress : ${{ github.ref_name != 'main' }}
1010
11+ # Declare default permissions as read only.
12+ permissions : read-all
13+
1114jobs :
1215 build :
1316 runs-on : ubuntu-latest
You can’t perform that action at this time.
0 commit comments