From 7f3b9949944806cdf4ea432505a1291c2f84af58 Mon Sep 17 00:00:00 2001 From: Alex Date: Mon, 7 Nov 2022 15:16:39 +0200 Subject: [PATCH] feat(repo): restrict permissions on github actions (#12909) Signed-off-by: Alex --- .github/workflows/e2e-matrix.yml | 3 +++ .github/workflows/e2e-windows.yml | 4 ++++ .github/workflows/npm-audit.yml | 4 ++++ .github/workflows/schedule-stale.yml | 5 +++++ 4 files changed, 16 insertions(+) diff --git a/.github/workflows/e2e-matrix.yml b/.github/workflows/e2e-matrix.yml index e20e48ec24ebc..559522194e993 100644 --- a/.github/workflows/e2e-matrix.yml +++ b/.github/workflows/e2e-matrix.yml @@ -10,8 +10,11 @@ on: required: false default: false +permissions: {} jobs: e2e: + permissions: + contents: read # to fetch code (actions/checkout) runs-on: ${{ matrix.os }} strategy: matrix: diff --git a/.github/workflows/e2e-windows.yml b/.github/workflows/e2e-windows.yml index 699f7e90b03bd..e94d4a9cdad7b 100644 --- a/.github/workflows/e2e-windows.yml +++ b/.github/workflows/e2e-windows.yml @@ -10,8 +10,12 @@ on: required: false default: false +permissions: {} jobs: e2e: + permissions: + contents: read # to fetch code (actions/checkout) + runs-on: windows-latest strategy: matrix: diff --git a/.github/workflows/npm-audit.yml b/.github/workflows/npm-audit.yml index 9e747f639d92a..4b15e9f60303e 100644 --- a/.github/workflows/npm-audit.yml +++ b/.github/workflows/npm-audit.yml @@ -5,8 +5,12 @@ on: - cron: "0 0 * * *" workflow_dispatch: +permissions: {} jobs: audit: + permissions: + contents: read # to fetch code (actions/checkout) + runs-on: ubuntu-latest steps: diff --git a/.github/workflows/schedule-stale.yml b/.github/workflows/schedule-stale.yml index 8234c0bc0c8f2..af780fbe4d601 100644 --- a/.github/workflows/schedule-stale.yml +++ b/.github/workflows/schedule-stale.yml @@ -2,8 +2,13 @@ on: schedule: - cron: "0 0 * * *" name: Stale Bot workflow +permissions: {} jobs: build: + permissions: + issues: write # to close stale issues (actions/stale) + pull-requests: write # to close stale PRs (actions/stale) + name: stale runs-on: ubuntu-latest steps: