From fe267f8ab0ec69d049d632444c8b6b6255342d1e Mon Sep 17 00:00:00 2001 From: Alex Date: Tue, 27 Sep 2022 00:01:39 +0200 Subject: [PATCH] build: harden coverity.yml permissions Signed-off-by: Alex --- .github/workflows/coverity.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml index d5cf381fc0..b86c00a5c1 100644 --- a/.github/workflows/coverity.yml +++ b/.github/workflows/coverity.yml @@ -6,6 +6,9 @@ on: # send data to Coverity daily at midnight - cron: '0 0 * * *' +permissions: + contents: read # to fetch code (actions/checkout) + jobs: build: runs-on: ubuntu-latest -- 2.47.2