trendvis
trendvis copied to clipboard
CI: Harden GHA configuration
Apply recommended hardening steps including:
- pinning to a SHA any actions used
- not persisting the read token on checkout
- setting the default permissions
- adding a depandabot file for GHA
I did not do any updating as part of this wave of PRs. The plan in my head was to rely on dependabot to fix that in a second pass.