Procházet zdrojové kódy

Merge pull request #4734 from sashashura/patch-7

GitHub Workflows security hardening
Kim Kulling před 3 roky
rodič
revize
ca11fceb65
2 změnil soubory, kde provedl 6 přidání a 0 odebrání
  1. 3 0
      .github/workflows/ccpp.yml
  2. 3 0
      .github/workflows/sanitizer.yml

+ 3 - 0
.github/workflows/ccpp.yml

@@ -6,6 +6,9 @@ on:
   pull_request:
   pull_request:
     branches: [ master ]
     branches: [ master ]
 
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
 jobs:
   job:
   job:
     name: ${{ matrix.name }}-build-and-test
     name: ${{ matrix.name }}-build-and-test

+ 3 - 0
.github/workflows/sanitizer.yml

@@ -6,6 +6,9 @@ on:
   pull_request:
   pull_request:
     branches: [ master ]
     branches: [ master ]
 
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
 jobs:
   job1:
   job1:
     name: adress-sanitizer
     name: adress-sanitizer