Skip to content

Conversation

@zerosnacks
Copy link
Member

By assigning

permissions: {}

we disable all permissions by default

we then grant it on a per-job basis to exactly what is strictly required

@zerosnacks zerosnacks marked this pull request as ready for review September 17, 2025 13:19
@zerosnacks zerosnacks enabled auto-merge (squash) September 17, 2025 13:19
@zerosnacks zerosnacks merged commit 975c10c into master Sep 17, 2025
25 checks passed
@zerosnacks zerosnacks deleted the zerosnacks/harden-ci-permissions branch September 17, 2025 13:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants