Browse Source

Update release.yaml (#179)

Bernhard Fröhlich 6 months ago
parent
commit
ccaf614b6b
1 changed files with 6 additions and 3 deletions
  1. 6 3
      .github/workflows/release.yaml

+ 6 - 3
.github/workflows/release.yaml

@@ -4,9 +4,8 @@ on:
   release:
   release:
     types: [created]
     types: [created]
 
 
-permissions:
-    contents: write
-    packages: write
+# Declare default permissions as read only.
+permissions: read-all
 
 
 jobs:
 jobs:
   releases-matrix:
   releases-matrix:
@@ -16,6 +15,10 @@ jobs:
       matrix:
       matrix:
         goos: [freebsd, linux, windows]
         goos: [freebsd, linux, windows]
         goarch: [amd64, arm64]
         goarch: [amd64, arm64]
+    permissions:
+        contents: write
+        packages: write
+
     steps:
     steps:
     - name: Harden Runner
     - name: Harden Runner
       uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4
       uses: step-security/harden-runner@cb605e52c26070c328afc4562f0b4ada7618a84e # v2.10.4