1
0
mirror of https://github.com/django/django.git synced 2025-11-07 07:15:35 +00:00

Restricted permissions for GitHub tokens.

This commit is contained in:
Mariusz Felisiak
2022-08-04 20:00:35 +02:00
committed by GitHub
parent 7e5c8fc51f
commit 5f76002500
6 changed files with 20 additions and 0 deletions

View File

@@ -16,6 +16,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }} group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true cancel-in-progress: true
permissions:
contents: read
jobs: jobs:
docs: docs:
# OS must be the same as on djangoproject.com. # OS must be the same as on djangoproject.com.

View File

@@ -14,6 +14,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }} group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true cancel-in-progress: true
permissions:
contents: read
jobs: jobs:
flake8: flake8:
name: flake8 name: flake8

View File

@@ -4,6 +4,10 @@ on:
pull_request_target: pull_request_target:
types: [opened] types: [opened]
permissions:
issues: write
pull-requests: read
jobs: jobs:
build: build:
name: Hello new contributor name: Hello new contributor

View File

@@ -7,6 +7,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }} group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true cancel-in-progress: true
permissions:
contents: read
jobs: jobs:
windows: windows:
runs-on: windows-latest runs-on: windows-latest

View File

@@ -5,6 +5,10 @@ on:
- cron: '42 2 * * *' - cron: '42 2 * * *'
workflow_dispatch: workflow_dispatch:
permissions:
actions: write
contents: read
jobs: jobs:
trigger-runs: trigger-runs:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View File

@@ -14,6 +14,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }} group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true cancel-in-progress: true
permissions:
contents: read
jobs: jobs:
windows: windows:
runs-on: windows-latest runs-on: windows-latest