From 22bdb10c4152f36020109ae40cb23d59b2eefd31 Mon Sep 17 00:00:00 2001 From: StepSecurity Bot Date: Tue, 16 Apr 2024 02:38:12 +0000 Subject: [PATCH] [StepSecurity] ci: Harden GitHub Actions Signed-off-by: StepSecurity Bot --- .github/workflows/codeql.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 43f73e08e5c4..656149880c08 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -19,6 +19,9 @@ on: schedule: - cron: '41 23 * * 2' +permissions: + contents: read + jobs: analyze: name: Analyze (${{ matrix.language }})