Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add read-only top-level permissions to cifuzz.yml #4191

Merged
merged 1 commit into from Apr 12, 2023

Conversation

pnacht
Copy link
Contributor

@pnacht pnacht commented Apr 12, 2023

Fixes #4190.

As mentioned in the issue, this PR adds read-only token permissions to the cifuzz.yml workflow, making it compatible with the other workflows (they were fixed in #3639). This reduces the risk of supply-chain attacks on the project.

Signed-off-by: Pedro Kaj Kjellerup Nacht <pnacht@google.com>
@behdad behdad merged commit 26c719e into harfbuzz:main Apr 12, 2023
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add read-only permissions to cifuzz.yml
2 participants