chore: Set permissions for GitHub actions
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.
- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions
https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests
Signed-off-by: naveen [email protected]
- Test Formalities / Test Formalities (pull_request) fails for you. Would you mind to fix it?
- Test Formalities / Test Formalities (pull_request) fails for you. Would you mind to fix it?
Can I do that in a future PR? Thanks
No. Signed-off-by is required to all commits, which we have in OpenWrt repositories.
Kind reminder, or else I will close this pull request within a few days.
Kind reminder, or else I will close this pull request within a few days.
I don't have time now. Apologies for not getting back sooner.
And you have time for response, that's interesting because both things take the same amount of time.
Closing. If you will have time in the future, which I doubt (TBH), then re-open this pull request or create a new one.