GitHub Workflows security hardening
@ -3,8 +3,13 @@ on:
schedule:
- cron: "30 0 * * *"
permissions: {}
jobs:
close-issues:
permissions:
issues: write # to close stale issues (actions/stale)
pull-requests: write # to close stale PRs (actions/stale)
runs-on: ubuntu-latest
steps:
- uses: actions/stale@v3
@ -2,6 +2,9 @@ name: "submit"
on:
workflow_dispatch:
contents: read
build:
@ -3,6 +3,9 @@ on:
push:
pull_request:
contents: read # to fetch code (actions/checkout)
validate:
name: Validate