From 80c8ef36929a8bcd43596b29d4866f4ba6239809 Mon Sep 17 00:00:00 2001 From: Alex Date: Tue, 20 Sep 2022 08:16:56 +0100 Subject: [PATCH] Update lock.yml Harden workflow permissions --- .github/workflows/lock.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/lock.yml b/.github/workflows/lock.yml index d3ea54200..30b12e76c 100644 --- a/.github/workflows/lock.yml +++ b/.github/workflows/lock.yml @@ -4,8 +4,14 @@ on: schedule: - cron: '* 6 * * *' +permissions: + contents: read + jobs: lock: + permissions: + issues: write + pull-requests: write runs-on: ubuntu-latest steps: - uses: dessant/lock-threads@v2.0.1