Skip to content

Add read-only token permissions#525

Closed
pnacht wants to merge 1 commit intoprometheus:masterfrom
pnacht:fix_token_permissions
Closed

Add read-only token permissions#525
pnacht wants to merge 1 commit intoprometheus:masterfrom
pnacht:fix_token_permissions

Conversation

@pnacht
Copy link

@pnacht pnacht commented May 19, 2023

Fixes prometheus/prometheus#12379.

This PR adds read-only token permissions to the golangci-lint.yml workflow to protect the project from supply-chain attacks. See the linked issue for details.

Signed-off-by: Pedro Kaj Kjellerup Nacht <pnacht@google.com>
@discordianfish
Copy link
Member

This should be changed in prometheus/common which is copied automatically to all other repos

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set read-only workflow permissions

2 participants