workflows/*: add security hardening (#8518)

pull/1/head
Alex 2022-09-28 20:17:33 +03:00 committed by GitHub
parent 163f2452da
commit 0fbe2488eb
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
3 changed files with 12 additions and 0 deletions

View File

@ -2,6 +2,9 @@ name: CI
on: ['push', 'pull_request']
permissions:
contents: read # to fetch code (actions/checkout)
jobs:
ci:
runs-on: ubuntu-latest

View File

@ -4,8 +4,12 @@ on:
push:
branches: ['main']
permissions: {}
jobs:
mirror:
permissions:
contents: write # to update branch
runs-on: ubuntu-latest
steps:

View File

@ -4,8 +4,13 @@ on:
schedule:
- cron: '0 0 * * *'
permissions: {}
jobs:
stale:
permissions:
issues: write # to close stale issues (actions/stale)
pull-requests: write # to close stale PRs (actions/stale)
runs-on: ubuntu-latest
steps: