From 84abd9f519a9196bcdb06e8734dc468f48e52439 Mon Sep 17 00:00:00 2001 From: Terri Oda Date: Fri, 31 May 2024 09:55:55 -0700 Subject: [PATCH] ci: openSSF scorecard fixes, fix build-wheel (#4149) Signed-off-by: Terri Oda --- .github/workflows/build-wheel.yml | 4 +++- .github/workflows/testing.yml | 2 ++ 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build-wheel.yml b/.github/workflows/build-wheel.yml index 56ccf23b33..627f5d4987 100644 --- a/.github/workflows/build-wheel.yml +++ b/.github/workflows/build-wheel.yml @@ -1,5 +1,7 @@ name: Build pip wheel +permissions: read-all + on: push: branches: [ "main" ] @@ -17,7 +19,7 @@ on: matrix: python-version: - "3.12" - if: github.repository == 'intel/cve-bin-tool' && github.ref == 'refs/heads/main' # run on origin repo only + if: github.repository == 'intel/cve-bin-tool' # run on origin repo only steps: - name: Harden Runner uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1 diff --git a/.github/workflows/testing.yml b/.github/workflows/testing.yml index 3a5e9781c2..935fbce7d7 100644 --- a/.github/workflows/testing.yml +++ b/.github/workflows/testing.yml @@ -1,5 +1,7 @@ name: Testing +permissions: read-all + on: push: pull_request: