From 0c3b2881c5abff8f6f8030e5abdd0d48bf6e019a Mon Sep 17 00:00:00 2001 From: robert-cronin Date: Fri, 29 Nov 2024 00:03:41 +0000 Subject: [PATCH] Reduce scorecard workflow permissions scope Signed-off-by: robert-cronin --- .github/workflows/scorecard.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7896fddcf5..e4d3ceb225 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -15,7 +15,8 @@ on: branches: [ "main" ] # Declare default permissions as read only. -permissions: read-all +permissions: + contents: read jobs: analysis: