Set least privileged token permission for GitHub Actions (#3155)

Signed-off-by: Ashish Kurmi <akurmi@stepsecurity.io>
pull/3198/head
Ashish Kurmi 2 years ago committed by GitHub
parent e5af37bc8c
commit da51adc276
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -9,6 +9,9 @@ on:
description: 'Image tag'
required: true
default: 'test'
permissions:
contents: read
jobs:
image:
name: Build Image from Dockerfile and binaries

@ -3,6 +3,9 @@ name: goreleaser
on:
workflow_dispatch:
permissions:
contents: read
jobs:
goreleaser:
runs-on: ubuntu-latest

@ -8,8 +8,14 @@ on:
description: 'In debug mod'
required: false
default: 'false'
permissions:
contents: read
jobs:
stale:
permissions:
issues: write # for actions/stale to close stale issues
pull-requests: write # for actions/stale to close stale PRs
runs-on: ubuntu-latest
steps:
- uses: actions/stale@v6

Loading…
Cancel
Save