From 8886162bbab9d93420ed09ae890c80972b7c7247 Mon Sep 17 00:00:00 2001 From: Alex Date: Mon, 26 Sep 2022 20:05:10 +0200 Subject: [PATCH] build: harden lock.yml permissions Signed-off-by: Alex --- .github/workflows/lock.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/lock.yml b/.github/workflows/lock.yml index 83af1dd62..a74cd73ea 100644 --- a/.github/workflows/lock.yml +++ b/.github/workflows/lock.yml @@ -5,8 +5,13 @@ on: schedule: - cron: '0 0 * * *' +permissions: {} jobs: lock: + permissions: + issues: write # to lock issues (dessant/lock-threads) + pull-requests: write # to lock PRs (dessant/lock-threads) + runs-on: ubuntu-latest steps: - uses: dessant/lock-threads@v2