Skip to content

Commit c283742

Browse files
authored
Merge pull request #236 from nicolasbock/alert-autofix-5
Potential fix for code scanning alert no. 5: Workflow does not contain permissions
2 parents 8603671 + d6f92de commit c283742

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

.github/workflows/publish.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@ jobs:
99
build:
1010
runs-on: ubuntu-latest
1111
name: Publish PyPI Package
12+
permissions:
13+
contents: read
1214
steps:
1315
- name: Check out sources
1416
uses: actions/checkout@v4
@@ -44,6 +46,7 @@ jobs:
4446
name: pypi
4547
url: https://pypi.org/p/ebuildtester
4648
permissions:
49+
contents: read
4750
id-token: write # IMPORTANT: mandatory for trusted publishing
4851

4952
steps:

0 commit comments

Comments
 (0)