From 213a2756275d272ae0f86516f70227f241944dd9 Mon Sep 17 00:00:00 2001 From: Alex Date: Mon, 26 Sep 2022 23:10:05 +0200 Subject: [PATCH] build: harden stale.yml permissions Signed-off-by: Alex --- .github/workflows/stale.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/stale.yml b/.github/workflows/stale.yml index a592fb5c7..f381ba3aa 100644 --- a/.github/workflows/stale.yml +++ b/.github/workflows/stale.yml @@ -3,8 +3,13 @@ on: schedule: - cron: "30 0 * * *" +permissions: {} jobs: close-issues: + permissions: + issues: write # to close stale issues (actions/stale) + pull-requests: write # to close stale PRs (actions/stale) + runs-on: ubuntu-latest steps: - uses: actions/stale@v3