Skip to content

Commit 0fc1f74

Browse files
committed
add permissions and pin SHA
1 parent a42189a commit 0fc1f74

File tree

2 files changed

+7
-3
lines changed

2 files changed

+7
-3
lines changed

.github/workflows/lint.yaml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,14 @@
11
name: Lint (Rubocop)
22
on: [push, pull_request, workflow_dispatch]
3+
permissions:
4+
contents: read
35
jobs:
46
rubocop:
57
runs-on: ubuntu-latest
68
steps:
79
- uses: actions/checkout@v4
810
- name: Setup Ruby
9-
uses: ruby/setup-ruby@v1
11+
uses: ruby/setup-ruby@a6e6f86333f0a2523ece813039b8b4be04560854 # v1.190.0
1012
- name: Install dependencies
1113
run: |
1214
bundle install --jobs 4 --retry 3

.github/workflows/spec-tests.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,13 @@
11
name: Spec Tests (Rspec)
2-
on: [push, pull_request, workflow_dispatch]
2+
on: [pull_request, workflow_dispatch]
3+
permissions:
4+
contents: read
35
jobs:
46
octofacts-rspec:
57
runs-on: ubuntu-latest
68
steps:
79
- uses: actions/checkout@v4
8-
- uses: ruby/setup-ruby@v1
10+
- uses: ruby/setup-ruby@a6e6f86333f0a2523ece813039b8b4be04560854 # v1.190.0
911
- name: Install dependencies
1012
run: |
1113
bundle install --jobs 4 --retry 3

0 commit comments

Comments
 (0)