On Sat, Oct 16, 2021 at 06:10:26PM +0200, Tim Duesterhus wrote:
> This change locks down the permissions of the access token in GitHub Actions
> to
> only allow reading the repository contents and nothing else.
(...)
This series and the coccinelle one applied, thanks Tim!
Willy
This change locks down the permissions of the access token in GitHub Actions to
only allow reading the repository contents and nothing else.
see
https://docs.github.com/en/actions/security-guides/automatic-token-authentication#permissions-for-the-github_token
---
.github/workflows/codespell.yml
2 matches
Mail list logo