Commit a5b690e
committed
Give the two workflows without a permissions block the least they need
sha-pinning-check.yml and update-pr-branch.yml ran with the default
GITHUB_TOKEN permissions, which zizmor (excessive-permissions) and
CodeQL (actions/missing-workflow-permissions) both flagged. The pin
check only checks the repository out and reads its workflow files, so
it gets contents: read. update-pr-branch reads and updates the pull
requests with BOT_PAT, the only token the action reads, so the
workflow's own token gets no permissions at all.1 parent 5c93489 commit a5b690e
2 files changed
Lines changed: 7 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
9 | 12 | | |
10 | 13 | | |
11 | 14 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
10 | 14 | | |
11 | 15 | | |
12 | 16 | | |
| |||
0 commit comments