Skip to content

Commit abbabfc

Browse files
authored
Merge pull request #29 from kpumuk/fix/scorecard-token-permissions
Restrict release workflow token permissions
2 parents a8811a7 + cc6dfaf commit abbabfc

1 file changed

Lines changed: 5 additions & 3 deletions

File tree

.github/workflows/release.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,15 +6,17 @@ on:
66
- "v*"
77

88
permissions:
9-
contents: write
10-
attestations: write
11-
id-token: write
9+
contents: read
1210

1311
jobs:
1412
goreleaser:
1513
name: release
1614
runs-on: ubuntu-latest
1715
environment: release
16+
permissions:
17+
contents: write
18+
attestations: write
19+
id-token: write
1820
steps:
1921
- name: Checkout
2022
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

0 commit comments

Comments
 (0)