Skip to content

Commit 1c7bf42

Browse files
Scope GITHUB_TOKEN permissions per job (#480)
A job with no `permissions:` block inherits whatever the repository hands out. Each block added here grants what that job's own steps need and nothing more. Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>
1 parent 656ada0 commit 1c7bf42

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

‎.github/workflows/ci.buld.yml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,12 @@ name: Run tests and build
22

33
on: [push]
44

5+
permissions: {}
6+
57
jobs:
68
build:
9+
permissions:
10+
contents: read
711
runs-on: ubuntu-latest
812

913
steps:
@@ -34,6 +38,8 @@ jobs:
3438

3539

3640
docker:
41+
permissions:
42+
contents: read
3743
runs-on: ubuntu-latest
3844

3945
needs: build

0 commit comments

Comments
 (0)