From 008e9a335dc32c4662aa56eb67487ddd777f2147 Mon Sep 17 00:00:00 2001 From: Alex Low Date: Mon, 19 Sep 2022 12:20:37 +0200 Subject: build: harden GitHub workflow permissions Grant pull-requests write permission to the labeler workflow and read-only to everything else. Signed-off-by: Alex Low [ wrap to 80 columns and fix wrong author as requested by author itself ] Signed-off-by: Christian Marangi (cherry picked from commit 715259940776843d8799bc39de8eb50eb764189b) --- .github/workflows/tools.yml | 3 +++ 1 file changed, 3 insertions(+) (limited to '.github/workflows/tools.yml') diff --git a/.github/workflows/tools.yml b/.github/workflows/tools.yml index 76cbd30db7..e089e26193 100644 --- a/.github/workflows/tools.yml +++ b/.github/workflows/tools.yml @@ -5,6 +5,9 @@ on: paths: - 'tools/**' +permissions: + contents: read + jobs: build: name: Build tools on ${{ matrix.os }} -- cgit v1.2.3