Skip to content

Commit 8a23bab

Browse files
[StepSecurity] ci: Harden GitHub Actions (#3134)
Signed-off-by: StepSecurity Bot <[email protected]>
1 parent 184eb94 commit 8a23bab

File tree

4 files changed

+19
-0
lines changed

4 files changed

+19
-0
lines changed

.github/workflows/codeql-analysis.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,15 @@ concurrency:
1313
group: ${{ github.ref_name }}-codeql
1414
cancel-in-progress: true
1515

16+
permissions: # added using https://github.com/step-security/secure-workflows
17+
contents: read
18+
1619
jobs:
1720
analyze:
21+
permissions:
22+
actions: read # for github/codeql-action/init to get workflow details
23+
contents: read # for actions/checkout to fetch code
24+
security-events: write # for github/codeql-action/autobuild to send a status report
1825
name: Analyze
1926
runs-on: ubuntu-latest
2027

.github/workflows/fossa.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,9 @@ concurrency:
1313
group: ${{ github.ref_name }}-fossa
1414
cancel-in-progress: true
1515

16+
permissions: # added using https://github.com/step-security/secure-workflows
17+
contents: read
18+
1619
jobs:
1720

1821
scan:

.github/workflows/labeler.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ name: "Pull Request Labeler"
22
on:
33
- pull_request_target
44

5+
permissions: # added using https://github.com/step-security/secure-workflows
6+
contents: read
7+
58
jobs:
69
triage:
710
permissions:

.github/workflows/stale.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,14 @@ on:
33
schedule:
44
- cron: '30 1 * * *'
55

6+
permissions: # added using https://github.com/step-security/secure-workflows
7+
contents: read
8+
69
jobs:
710
stale:
11+
permissions:
12+
issues: write # for actions/stale to close stale issues
13+
pull-requests: write # for actions/stale to close stale PRs
814
runs-on: ubuntu-20.04
915
steps:
1016
- uses: actions/stale@v6

0 commit comments

Comments
 (0)