ci: restrict the CI actions permissions
This commit is contained in:
		
							
								
								
									
										7
									
								
								.github/workflows/conventional-commits.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										7
									
								
								.github/workflows/conventional-commits.yml
									
									
									
									
										vendored
									
									
								
							| @@ -4,10 +4,17 @@ on: | ||||
|   pull_request: | ||||
|     types: [ opened, synchronize, reopened, edited ] | ||||
|  | ||||
| permissions: { } | ||||
|  | ||||
| jobs: | ||||
|   build: | ||||
|     name: conventional commits | ||||
|     runs-on: ubuntu-22.04 | ||||
|     permissions: | ||||
|       contents: read | ||||
|       pull-requests: read | ||||
|       packages: read | ||||
|       statuses: write | ||||
|     steps: | ||||
|       - name: checkout code | ||||
|         uses: actions/checkout@v3 | ||||
|   | ||||
| @@ -4,10 +4,17 @@ on: | ||||
|   pull_request: | ||||
|     types: [ opened, synchronize, reopened, edited ] | ||||
|  | ||||
| permissions: { } | ||||
|  | ||||
| jobs: | ||||
|   build: | ||||
|     name: conventional pull requests | ||||
|     runs-on: ubuntu-22.04 | ||||
|     permissions: | ||||
|       contents: read | ||||
|       pull-requests: read | ||||
|       packages: read | ||||
|       statuses: write | ||||
|     steps: | ||||
|       - name: conventional pull requests check | ||||
|         uses: ytanikin/PRConventionalCommits@1.1.0 | ||||
|   | ||||
							
								
								
									
										1
									
								
								.github/workflows/lint.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										1
									
								
								.github/workflows/lint.yml
									
									
									
									
										vendored
									
									
								
							| @@ -12,6 +12,7 @@ jobs: | ||||
|     runs-on: ubuntu-latest | ||||
|     permissions: | ||||
|       contents: read | ||||
|       pull-requests: read | ||||
|       packages: read | ||||
|       statuses: write | ||||
|     steps: | ||||
|   | ||||
		Reference in New Issue
	
	Block a user