From b4bbd93ff2890686ea4afcd67475f3b19b6cb8d9 Mon Sep 17 00:00:00 2001 From: Alex Date: Thu, 8 Dec 2022 20:35:52 +0200 Subject: [PATCH] build: harden continuous-integration.yml permissions Signed-off-by: Alex --- .github/workflows/continuous-integration.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/continuous-integration.yml b/.github/workflows/continuous-integration.yml index 8caa14ee89..17aaa42042 100644 --- a/.github/workflows/continuous-integration.yml +++ b/.github/workflows/continuous-integration.yml @@ -4,6 +4,9 @@ name: Build and Test on: [push, pull_request] +permissions: + contents: read # to fetch code (actions/checkout) + jobs: ci: runs-on: ${{ matrix.operating-system }}