ci: restrict GITHUB_TOKEN permissions

Signed-off-by: Rifa Achrinza <25147899+achrinza@users.noreply.github.com>
This commit is contained in:
Rifa Achrinza 2021-09-11 14:05:53 +08:00
parent 5aa2d71a23
commit 9a58695740
1 changed files with 7 additions and 0 deletions

View File

@ -9,6 +9,8 @@ on:
schedule:
- cron: '0 2 * * 1' # At 02:00 on Monday
permissions: {}
jobs:
test:
name: Test
@ -102,6 +104,11 @@ jobs:
codeql:
name: CodeQL
runs-on: ubuntu-latest
permissions:
# See: https://github.com/github/codeql-action/blob/008b2cc71c4cf3401f45919d8eede44a65b4a322/README.md#usage
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v2