Skip to content

Commit 6ccc8cf

Browse files
authored
Merge pull request #786 from Azure/jeetgarg-patch-2
Update dependency-review.yml with job level permission as Read
2 parents ee7fd27 + 2ab8452 commit 6ccc8cf

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

.github/workflows/dependency-review.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
# Source repository: https://github.com/actions/dependency-review-action
66
# Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
77
name: 'Dependency Review'
8+
89
on: [pull_request]
910

1011
permissions:
@@ -13,6 +14,10 @@ permissions:
1314
jobs:
1415
dependency-review:
1516
runs-on: ubuntu-latest
17+
18+
permissions:
19+
contents: read
20+
1621
steps:
1722
- name: 'Checkout Repository'
1823
uses: actions/checkout@v4

0 commit comments

Comments
 (0)