From 8b1a836e7dbb44034aeee8dbf3826e1f5c2442fb Mon Sep 17 00:00:00 2001 From: Alex Date: Wed, 17 May 2023 11:39:40 +0200 Subject: [PATCH] GitHub Workflows security hardening (#1180) * build: harden golangci-lint.yml permissions Signed-off-by: Alex * Update golangci-lint.yml Signed-off-by: Alex --------- Signed-off-by: Alex --- .github/workflows/golangci-lint.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/golangci-lint.yml b/.github/workflows/golangci-lint.yml index 6034bcbf8..b19948514 100644 --- a/.github/workflows/golangci-lint.yml +++ b/.github/workflows/golangci-lint.yml @@ -10,8 +10,15 @@ on: - ".golangci.yml" pull_request: +permissions: + contents: read # to fetch code (actions/checkout) + jobs: golangci: + permissions: + contents: read # to fetch code (actions/checkout) + pull-requests: read # to fetch pull requests (golangci/golangci-lint-action) + name: lint runs-on: ubuntu-latest steps: