From dc095d06803afdf42758a35540335762595fe35a Mon Sep 17 00:00:00 2001 From: Taiki Endo Date: Sun, 26 Mar 2023 16:32:28 +0900 Subject: [PATCH] Minimize GITHUB_TOKEN permissions Refs: https://github.blog/changelog/2021-04-20-github-actions-control-permissions-for-github_token --- .github/workflows/ci.yml | 7 +++++++ .github/workflows/release.yml | 3 +++ 2 files changed, 10 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e13e7aa..84e190e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,5 +1,8 @@ name: CI +permissions: + contents: read + on: pull_request: push: @@ -83,6 +86,10 @@ jobs: RUSTFLAGS: ${{ env.RUSTFLAGS }} -Z randomize-layout security_audit: + permissions: + checks: write + contents: read + issues: write runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index be57bd1..d61ac7a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,5 +1,8 @@ name: Release +permissions: + contents: write + on: push: tags: