Skip to content

Conversation

zerosnacks
Copy link
Member

By assigning

permissions: {}

we disable all permissions by default

we then grant it on a per-job basis to exactly what is strictly required

@zerosnacks zerosnacks merged commit c3a0dd9 into main Sep 17, 2025
17 checks passed
@zerosnacks zerosnacks deleted the zerosnacks/harden-ci-permissions branch September 17, 2025 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants