diff --git a/.github/workflows/label-automerge.yml b/.github/workflows/label-automerge.yml index 1b0e2a5c..266f6f74 100644 --- a/.github/workflows/label-automerge.yml +++ b/.github/workflows/label-automerge.yml @@ -8,10 +8,21 @@ on: env: LABEL_NAME: 'automerge :bell:' +permissions: + contents: read + jobs: add-remove-label: + permissions: + issues: write # for dependabot to enable auto-label + repository-projects: write # for dependabot to enable auto-label runs-on: ubuntu-latest steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + - name: Update label run: | if [[ "${{ github.event.action }}" == "auto_merge_enabled" ]]; then diff --git a/.github/workflows/scorecards.yml b/.github/workflows/scorecards.yml index c8f2ca7a..9a87270d 100644 --- a/.github/workflows/scorecards.yml +++ b/.github/workflows/scorecards.yml @@ -27,6 +27,11 @@ jobs: actions: read steps: + - name: Harden Runner + uses: step-security/harden-runner@91182cccc01eb5e619899d80e4e971d6181294a7 # v2.10.1 + with: + egress-policy: audit + - name: "Checkout code" uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # tag=v4.2.1 with: