浏览代码

build: harden test.yml permissions
Signed-off-by: Alex <aleksandrosansan@gmail.com>

Alex 2 年之前
父节点
当前提交
d0c0e2fc02
共有 1 个文件被更改,包括 3 次插入0 次删除
  1. 3 0
      .github/workflows/test.yml

+ 3 - 0
.github/workflows/test.yml

@@ -34,6 +34,9 @@ concurrency:
 # - elasticsearch 7, django 4.0, python 3.8, postgres
 # - elasticsearch 7, django 4.1, python 3.9, sqlite, USE_EMAIL_USER_MODEL=yes
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
   test-sqlite:
     runs-on: ubuntu-latest