mirror of
https://github.com/zulip/zulip.git
synced 2025-11-02 04:53:36 +00:00
ci: Limit GitHub token permissions for workflows.
This limits the ability for an Action to do mischief with this token. Fixes #22786. Signed-off-by: Varun Sharma <varunsh@stepsecurity.io>
This commit is contained in:
3
.github/workflows/production-suite.yml
vendored
3
.github/workflows/production-suite.yml
vendored
@@ -33,6 +33,9 @@ defaults:
|
||||
run:
|
||||
shell: bash
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
production_build:
|
||||
# This job builds a release tarball from the current commit, which
|
||||
|
||||
Reference in New Issue
Block a user