From c7f93be000abda49ed84c8ddf60395355e2cf8c8 Mon Sep 17 00:00:00 2001 From: robert-cronin Date: Fri, 29 Nov 2024 00:03:41 +0000 Subject: [PATCH] Reduce scorecard workflow permissions scope Signed-off-by: robert-cronin --- .github/workflows/scorecard.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7896fddcf5..0c63ab49f1 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -15,7 +15,9 @@ on: branches: [ "main" ] # Declare default permissions as read only. -permissions: read-all +permissions: + contents: read + id-token: write jobs: analysis: