From a179735103442878d49df4d71066c2481d74d64a Mon Sep 17 00:00:00 2001 From: Alex Date: Tue, 23 Apr 2024 07:20:47 +0200 Subject: [PATCH] GitHub Workflows security hardening (#3884) Signed-off-by: sashashura <93376818+sashashura@users.noreply.github.com> --- .github/workflows/bad-pr.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/bad-pr.yml b/.github/workflows/bad-pr.yml index e53e0e30..bf5572e0 100644 --- a/.github/workflows/bad-pr.yml +++ b/.github/workflows/bad-pr.yml @@ -4,8 +4,13 @@ on: pull_request_target: types: [opened, reopened] +permissions: + contents: read + jobs: close-pr: + permissions: + pull-requests: write runs-on: ubuntu-latest if: "contains(github.event.pull_request.body, 'by deleting this comment block') || github.event.pull_request.body == ''" steps: