Updates the permissions block to be minimal

And adds a permissions block to the README.
This commit is contained in:
Andrew Eisenberg 2021-08-09 11:40:19 -07:00
parent 9e304b92ff
commit 21753283b1
3 changed files with 9 additions and 5 deletions

View file

@ -17,8 +17,6 @@ jobs:
versions: ${{ steps.compare.outputs.versions }}
permissions:
actions: read
contents: read
security-events: write
steps:
@ -68,8 +66,6 @@ jobs:
runs-on: ${{ matrix.os }}
permissions:
actions: read
contents: read
security-events: write
steps:

View file

@ -2,7 +2,7 @@
## [UNRELEASED]
No user facing changes.
- Update README to include a sample permissions block. [#689](https://github.com/github/codeql-action/pull/689)
## 1.0.10 - 03 Aug 2021

View file

@ -42,6 +42,14 @@ jobs:
# CodeQL runs on ubuntu-latest, windows-latest, and macos-latest
runs-on: ubuntu-latest
permissions:
# required for all workflows
security-events: write
# only required for workflows in private repositories
actions: read
contents: read
steps:
- name: Checkout repository
uses: actions/checkout@v2