From 459310bc9b95720db647fb99ee0b57d1c83da95a Mon Sep 17 00:00:00 2001 From: Alex Date: Sun, 25 Sep 2022 19:14:47 +0200 Subject: [PATCH] build: harden ci.yml permissions Signed-off-by: Alex --- .github/workflows/ci.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d717c8d25..6f74b063d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -3,6 +3,9 @@ on: pull_request: push: +permissions: + contents: read # to fetch code (actions/checkout) + jobs: test: strategy: