build: harden calibreapp-image-actions.yml permissions (#4555)

Signed-off-by: Alex <aleksandrosansan@gmail.com>

Signed-off-by: Alex <aleksandrosansan@gmail.com>
This commit is contained in:
Alex
2022-12-09 03:49:15 +02:00
committed by GitHub
parent 92ab7c1700
commit 7db2284564

View File

@@ -24,8 +24,13 @@ on:
workflow_dispatch: workflow_dispatch:
schedule: schedule:
- cron: "00 20 * * 0" - cron: "00 20 * * 0"
permissions: {}
jobs: jobs:
build: build:
permissions:
contents: write
pull-requests: write # to comment on pull request
name: calibreapp/image-actions name: calibreapp/image-actions
runs-on: ubuntu-latest runs-on: ubuntu-latest
# Only run on main repo on and PRs that match the main repo. # Only run on main repo on and PRs that match the main repo.