Skip to content

Commit 9d956a8

Browse files
committed
Set low top level permissions for workflows and increase where needed instead.
1 parent 44e33d6 commit 9d956a8

3 files changed

Lines changed: 8 additions & 36 deletions

File tree

.github/workflows/dependabot-automerge.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,15 @@ name: Dependabot auto-merge
44
on: pull_request
55

66
permissions:
7-
contents: write
8-
pull-requests: write
7+
contents: read
98

109
jobs:
1110
dependabot:
1211
runs-on: ubuntu-latest
1312
if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'FortnoxAB/changesets-java'
13+
permissions:
14+
contents: write
15+
pull-requests: write
1416
steps:
1517
- name: Harden the runner (Audit all outbound calls)
1618
uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2

.github/workflows/dependabot-changesets.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,15 @@ on:
44
pull_request: {}
55

66
permissions:
7-
pull-requests: read
8-
contents: write
7+
contents: read
98

109
jobs:
1110
generate-changeset:
1211
runs-on: ubuntu-latest
1312
if: github.event.pull_request.user.login == 'dependabot[bot]' && github.repository == 'FortnoxAB/changesets-java'
13+
permissions:
14+
pull-requests: read
15+
contents: write
1416
steps:
1517
- name: Harden the runner (Audit all outbound calls)
1618
uses: step-security/harden-runner@95d9a5deda9de15063e7595e9719c11c38c90ae2 # v2.13.2

.github/workflows/publish-site-ghpages.yml

Lines changed: 0 additions & 32 deletions
This file was deleted.

0 commit comments

Comments
 (0)