Harden CI permissions (#4950)

This commit is contained in:
Alexandru Ionut Tripon 2026-02-03 22:09:41 +00:00 committed by GitHub
commit 9e86c44f7c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
10 changed files with 40 additions and 9 deletions

View file

@ -10,10 +10,16 @@ on:
pull_request:
workflow_dispatch:
permissions: {}
jobs:
CodeQL:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v6