소스 검색

Merge pull request #4734 from sashashura/patch-7

GitHub Workflows security hardening
Kim Kulling 3 년 전
부모
커밋
ca11fceb65
2개의 변경된 파일6개의 추가작업 그리고 0개의 파일을 삭제
  1. 3 0
      .github/workflows/ccpp.yml
  2. 3 0
      .github/workflows/sanitizer.yml

+ 3 - 0
.github/workflows/ccpp.yml

@@ -6,6 +6,9 @@ on:
   pull_request:
     branches: [ master ]
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
   job:
     name: ${{ matrix.name }}-build-and-test

+ 3 - 0
.github/workflows/sanitizer.yml

@@ -6,6 +6,9 @@ on:
   pull_request:
     branches: [ master ]
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
   job1:
     name: adress-sanitizer