Skip to content

Commit 0265dc4

Browse files
gcanlinljharb
authored andcommitted
[actions] restrict permissions
1 parent b9b23e6 commit 0265dc4

File tree

5 files changed

+20
-0
lines changed

5 files changed

+20
-0
lines changed

.github/workflows/node-aught.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: 'Tests: node.js < 10'
22

33
on: [pull_request, push]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
tests:
710
uses: ljharb/actions/.github/workflows/node.yml@main

.github/workflows/node-pretest.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: 'Tests: pretest/posttest'
22

33
on: [pull_request, push]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
tests:
710
uses: ljharb/actions/.github/workflows/pretest.yml@main

.github/workflows/node-tens.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: 'Tests: node.js >= 10'
22

33
on: [pull_request, push]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
tests:
710
uses: ljharb/actions/.github/workflows/node.yml@main

.github/workflows/rebase.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,14 @@ name: Automatic Rebase
22

33
on: [pull_request_target]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
_:
10+
permissions:
11+
contents: write
12+
pull-requests: read
713
name: "Automatic Rebase"
814

915
runs-on: ubuntu-latest

.github/workflows/require-allow-edits.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,13 @@ name: Require “Allow Edits”
22

33
on: [pull_request_target]
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
_:
10+
permissions:
11+
pull-requests: read
712
name: "Require “Allow Edits”"
813

914
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)