From 7e85b5d66ae0cf5c6cf731a496c9041c47111b50 Mon Sep 17 00:00:00 2001 From: Chris Gavin Date: Thu, 22 Apr 2021 16:59:06 +0100 Subject: [PATCH] Restrict Actions token permissions in CodeQL workflow. --- .github/workflows/codeql.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 8d7adfd89..1f05cd018 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -13,6 +13,9 @@ jobs: outputs: versions: ${{ steps.compare.outputs.versions }} + permissions: + contents: read + steps: - uses: actions/checkout@v2 - name: Init with default CodeQL bundle from the VM image @@ -59,6 +62,11 @@ jobs: tools: ${{ fromJson(needs.check-codeql-versions.outputs.versions) }} runs-on: ${{ matrix.os }} + permissions: + contents: read + security-events: write + + steps: - uses: actions/checkout@v2 - uses: ./init