Skip to content

Commit 1d5f780

Browse files
committed
chore(ci): tighten workflow token permissions
1 parent 654c05f commit 1d5f780

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

.github/workflows/main.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,13 @@ on:
44
- push
55
- pull_request
66

7+
permissions: {}
8+
79
jobs:
810
lint:
911
runs-on: ubuntu-latest
12+
permissions:
13+
contents: read
1014
steps:
1115
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
1216
- name: Setup Python
@@ -25,6 +29,8 @@ jobs:
2529
- py312
2630
- py313
2731
- pypy3
32+
permissions:
33+
contents: read
2834
steps:
2935
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
3036
- name: Fedora Tox with ${{ matrix.tox_env }}
@@ -40,6 +46,8 @@ jobs:
4046
deploy:
4147
name: Build deploy
4248
runs-on: ubuntu-latest
49+
permissions:
50+
contents: read
4351
steps:
4452
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4553
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0

0 commit comments

Comments
 (0)