Commit 711317c
committed
ops: tighten workflow token permissions
Same pattern as runcycles/cycles-server#144. Rewrites the canonical
dependabot-auto-merge.yml top-level write block into top-level read-all
+ per-job writes. Addresses Token-Permissions criterion from OpenSSF
Scorecard.1 parent 276d253 commit 711317c
1 file changed
Lines changed: 7 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
7 | | - | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
11 | 12 | | |
12 | 13 | | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
13 | 17 | | |
14 | 18 | | |
15 | 19 | | |
| |||
0 commit comments