浏览代码

Set least privileged token permission for GitHub Actions (#3155)

Signed-off-by: Ashish Kurmi <akurmi@stepsecurity.io>
Ashish Kurmi 2 年之前
父节点
当前提交
da51adc276
共有 3 个文件被更改,包括 12 次插入0 次删除
  1. 3 0
      .github/workflows/build-and-push-image.yml
  2. 3 0
      .github/workflows/goreleaser.yml
  3. 6 0
      .github/workflows/stale.yml

+ 3 - 0
.github/workflows/build-and-push-image.yml

@@ -9,6 +9,9 @@ on:
         description: 'Image tag'
         required: true
         default: 'test'
+permissions:
+  contents: read
+
 jobs:
   image:
     name: Build Image from Dockerfile and binaries

+ 3 - 0
.github/workflows/goreleaser.yml

@@ -3,6 +3,9 @@ name: goreleaser
 on:
   workflow_dispatch:
 
+permissions:
+  contents: read
+
 jobs:
   goreleaser:
     runs-on: ubuntu-latest

+ 6 - 0
.github/workflows/stale.yml

@@ -8,8 +8,14 @@ on:
         description: 'In debug mod'
         required: false
         default: 'false'
+permissions:
+  contents: read
+
 jobs:
   stale:
+    permissions:
+      issues: write  # for actions/stale to close stale issues
+      pull-requests: write  # for actions/stale to close stale PRs
     runs-on: ubuntu-latest
     steps:
     - uses: actions/stale@v6