firefly-iii/.github
naveensrinivasan a963e1bc03 Set permissions for GitHub actions
- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

 Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

Signed-off-by: naveensrinivasan <172697+naveensrinivasan@users.noreply.github.com>
2022-04-07 22:58:30 +00:00
..
assets/img Fix readme in dev. 2021-08-10 18:05:40 +02:00
ISSUE_TEMPLATE Update bug.yml 2021-12-28 08:54:04 +01:00
workflows Set permissions for GitHub actions 2022-04-07 22:58:30 +00:00
code_of_conduct.md Update email address. 2020-02-16 14:00:57 +01:00
contributing.md Update contributing guidelines. 2020-12-05 14:52:55 +01:00
dependabot.yml Update dependabot.yml 2022-01-25 06:03:12 +01:00
funding.yml Code changes for v540 2020-09-18 12:16:47 +02:00
its_you_not_me.md Update its_you_not_me.md 2022-03-31 04:21:50 +00:00
mergify.yml Update meta files for new release. 2022-02-28 06:40:34 +01:00
pull_request_template.md Update PR template 2021-07-03 12:34:47 +02:00
security.md Small textual changes 2020-07-11 07:18:51 +02:00
stale.yml Update meta data for new release. 2021-11-12 20:07:09 +01:00
support.md Update support.md 2022-03-31 04:16:47 +00:00