瀏覽代碼

build: harden main-ci.yml permissions
Signed-off-by: Alex <aleksandrosansan@gmail.com>

Alex 2 年之前
父節點
當前提交
9402f8c104
共有 1 個文件被更改,包括 3 次插入0 次删除
  1. 3 0
      .github/workflows/main-ci.yml

+ 3 - 0
.github/workflows/main-ci.yml

@@ -11,6 +11,9 @@ on:
   schedule:
     - cron: '0 0 * * 0'
 
+permissions:
+  contents: read # to fetch code (actions/checkout)
+
 jobs:
   build-php:
     # Don't trigger on schedule event when in a fork