From f2fb44ccfef16a7564dd5333fb5ae961700fa989 Mon Sep 17 00:00:00 2001 From: Julien Mailleret <8582351+jmlrt@users.noreply.github.com> Date: Thu, 2 Jan 2025 11:01:20 +0100 Subject: [PATCH] Fix workflows security alerts --- .github/workflows/pre-commit.yml | 4 +++- .github/workflows/tests.yml | 2 ++ 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml index 65947d3..2f57659 100644 --- a/.github/workflows/pre-commit.yml +++ b/.github/workflows/pre-commit.yml @@ -7,8 +7,10 @@ on: jobs: pre-commit: + permissions: + contents: read runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-python@v5 - - uses: pre-commit/action@v3.0.1 + - uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd #v3.0.1 diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 52f3eb3..6e82bf5 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -7,6 +7,8 @@ on: jobs: tests: + permissions: + contents: read runs-on: ubuntu-latest steps: - uses: actions/checkout@v3