Skip to content

Commit db7c8e6

Browse files
add top-level permissions and pin actions
1 parent 3fa80e4 commit db7c8e6

File tree

2 files changed

+10
-4
lines changed

2 files changed

+10
-4
lines changed

.github/workflows/codeql.yml

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,9 @@ on:
1919
schedule:
2020
- cron: '00 10 * * 3'
2121

22+
# Declare default permissions as read only.
23+
permissions: read-all
24+
2225
jobs:
2326
analyze:
2427
name: Analyze (${{ matrix.language }})
@@ -59,7 +62,7 @@ jobs:
5962
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
6063
steps:
6164
- name: Checkout repository
62-
uses: actions/checkout@v4
65+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
6366

6467
# Add any setup steps before running the `github/codeql-action/init` action.
6568
# This includes steps like installing compilers or runtimes (`actions/setup-node`
@@ -69,7 +72,7 @@ jobs:
6972

7073
# Initializes the CodeQL tools for scanning.
7174
- name: Initialize CodeQL
72-
uses: github/codeql-action/init@v3
75+
uses: github/codeql-action/init@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9
7376
with:
7477
languages: ${{ matrix.language }}
7578
build-mode: ${{ matrix.build-mode }}
@@ -97,6 +100,6 @@ jobs:
97100
exit 1
98101
99102
- name: Perform CodeQL Analysis
100-
uses: github/codeql-action/analyze@v3
103+
uses: github/codeql-action/analyze@df559355d593797519d70b90fc8edd5db049e7a2 # v3.29.9
101104
with:
102105
category: "/language:${{matrix.language}}"

.github/workflows/release-debug.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,9 @@ env:
1919
REGISTRY: ghcr.io
2020
IMAGE_NAME: ${{ github.repository }}/distroless-debug
2121

22+
# Declare default permissions as read only.
23+
permissions: read-all
24+
2225
jobs:
2326
build:
2427
runs-on: ubuntu-latest
@@ -31,7 +34,7 @@ jobs:
3134

3235
steps:
3336
- name: Checkout repository
34-
uses: actions/checkout@v4
37+
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3538

3639
- name: Get image tag
3740
id: get_image_tag

0 commit comments

Comments
 (0)