From d6aec1031dd375eab393ab118774ef5b3b779037 Mon Sep 17 00:00:00 2001 From: "James M. Greene" Date: Wed, 22 Feb 2023 11:51:01 -0600 Subject: [PATCH] Restrict test workflow permissions to reading contents only --- .github/workflows/test.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 6937d5e..8d844c5 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -1,10 +1,14 @@ name: Run Tests + on: push: branches: - main pull_request: +permissions: + contents: read + jobs: test: runs-on: ubuntu-latest