Ver código fonte

Set GITHUB_TOKEN permissions to read only in OpenAPI workflow

Niels van Velzen 3 anos atrás
pai
commit
07b9ba2bb4
1 arquivos alterados com 2 adições e 0 exclusões
  1. 2 0
      .github/workflows/openapi.yml

+ 2 - 0
.github/workflows/openapi.yml

@@ -9,6 +9,7 @@ jobs:
   openapi-head:
     name: OpenAPI - HEAD
     runs-on: ubuntu-latest
+    permissions: read-all
     steps:
       - name: Checkout repository
         uses: actions/checkout@v2
@@ -34,6 +35,7 @@ jobs:
     name: OpenAPI - BASE
     if: ${{ github.base_ref != '' }}
     runs-on: ubuntu-latest
+    permissions: read-all
     steps:
       - name: Checkout repository
         uses: actions/checkout@v2