Skip to content

Commit ddb5781

Browse files
committed
CI: Restrict default permissions
Reduces risk of arbitrary code is run by attacker.
1 parent db4ad46 commit ddb5781

File tree

4 files changed

+8
-0
lines changed

4 files changed

+8
-0
lines changed

.github/workflows/basemap-data-hires.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
11
name: basemap-data-hires
2+
permissions:
3+
contents: read
24

35
env:
46
PKGDIR: "packages/basemap_data_hires"

.github/workflows/basemap-data.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
11
name: basemap-data
2+
permissions:
3+
contents: read
24

35
env:
46
PKGDIR: "packages/basemap_data"

.github/workflows/basemap-for-manylinux.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
11
name: basemap-for-manylinux
2+
permissions:
3+
contents: read
24

35
env:
46
PKGDIR: "packages/basemap"

.github/workflows/basemap-for-windows.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,6 @@
11
name: basemap-for-windows
2+
permissions:
3+
contents: read
24

35
env:
46
PKGDIR: "packages/basemap"

0 commit comments

Comments
 (0)