소스 검색

ci(smoke): set least-privilege GITHUB_TOKEN permissions

Add a top-level `permissions: contents: read` block so the smoke-test
workflow no longer inherits the repository default token permissions.
Resolves CodeQL actions/missing-workflow-permissions.
MHSanaei 20 시간 전
부모
커밋
a133282fc3
1개의 변경된 파일3개의 추가작업 그리고 0개의 파일을 삭제
  1. 3 0
      .github/workflows/smoke.yml

+ 3 - 0
.github/workflows/smoke.yml

@@ -15,6 +15,9 @@ on:
       - "deploy/**"
       - ".github/workflows/smoke.yml"
 
+permissions:
+  contents: read
+
 jobs:
   noninteractive-install:
     strategy: