Skip to content

Commit d6e597b

Browse files
author
jovanSAPFIONEER
committed
fix: restrict top-level permissions in dependabot-auto-merge.yml (Scorecard #55)
Move contents/pull-requests write to job-level only; top-level set to read-all so Scorecard TokenPermissionsID is satisfied
1 parent 500b67e commit d6e597b

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

.github/workflows/dependabot-auto-merge.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,14 +2,15 @@ name: Dependabot auto-merge
22

33
"on": pull_request
44

5-
permissions:
6-
contents: write
7-
pull-requests: write
5+
permissions: read-all
86

97
jobs:
108
auto-merge:
119
runs-on: ubuntu-latest
1210
if: github.actor == 'dependabot[bot]'
11+
permissions:
12+
contents: write
13+
pull-requests: write
1314
steps:
1415
- name: Fetch Dependabot metadata
1516
id: metadata

0 commit comments

Comments
 (0)