summaryrefslogtreecommitdiff
path: root/.github
diff options
context:
space:
mode:
authorMariusz Felisiak <felisiak.mariusz@gmail.com>2022-08-04 20:00:35 +0200
committerGitHub <noreply@github.com>2022-08-04 20:00:35 +0200
commit5f760025004bdb02f9844011033459c30347f215 (patch)
tree3ba5042c90cb124d38c913a6a53e3721d91af0af /.github
parent7e5c8fc51fa891234daf01b7957fdc4e087e2a1e (diff)
downloaddjango-5f760025004bdb02f9844011033459c30347f215.tar.gz
Restricted permissions for GitHub tokens.
Diffstat (limited to '.github')
-rw-r--r--.github/workflows/docs.yml3
-rw-r--r--.github/workflows/linters.yml3
-rw-r--r--.github/workflows/new_contributor_pr.yml4
-rw-r--r--.github/workflows/schedule_tests.yml3
-rw-r--r--.github/workflows/schedules.yml4
-rw-r--r--.github/workflows/tests.yml3
6 files changed, 20 insertions, 0 deletions
diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml
index 5208699e38..9975a632bf 100644
--- a/.github/workflows/docs.yml
+++ b/.github/workflows/docs.yml
@@ -16,6 +16,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
+permissions:
+ contents: read
+
jobs:
docs:
# OS must be the same as on djangoproject.com.
diff --git a/.github/workflows/linters.yml b/.github/workflows/linters.yml
index e24733172e..eaa11ced3c 100644
--- a/.github/workflows/linters.yml
+++ b/.github/workflows/linters.yml
@@ -14,6 +14,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
+permissions:
+ contents: read
+
jobs:
flake8:
name: flake8
diff --git a/.github/workflows/new_contributor_pr.yml b/.github/workflows/new_contributor_pr.yml
index 3efc556ef4..0848c01187 100644
--- a/.github/workflows/new_contributor_pr.yml
+++ b/.github/workflows/new_contributor_pr.yml
@@ -4,6 +4,10 @@ on:
pull_request_target:
types: [opened]
+permissions:
+ issues: write
+ pull-requests: read
+
jobs:
build:
name: Hello new contributor
diff --git a/.github/workflows/schedule_tests.yml b/.github/workflows/schedule_tests.yml
index 11c8ecce6e..4677a3ed32 100644
--- a/.github/workflows/schedule_tests.yml
+++ b/.github/workflows/schedule_tests.yml
@@ -7,6 +7,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
+permissions:
+ contents: read
+
jobs:
windows:
runs-on: windows-latest
diff --git a/.github/workflows/schedules.yml b/.github/workflows/schedules.yml
index d58af423ff..bd9cced240 100644
--- a/.github/workflows/schedules.yml
+++ b/.github/workflows/schedules.yml
@@ -5,6 +5,10 @@ on:
- cron: '42 2 * * *'
workflow_dispatch:
+permissions:
+ actions: write
+ contents: read
+
jobs:
trigger-runs:
runs-on: ubuntu-latest
diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml
index 6965960155..cfdc661560 100644
--- a/.github/workflows/tests.yml
+++ b/.github/workflows/tests.yml
@@ -14,6 +14,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
+permissions:
+ contents: read
+
jobs:
windows:
runs-on: windows-latest