Commit 53bef1b
CI: Harden gerrit-verify workflow permissions
Replace 'permissions: read-all' with least-privilege
'contents: read' (Sonar githubactions:S8234). Add
'--only-binary :all:' and pin tox on the ACT-only local
install step to lock resolved versions and prevent setup
script execution (Sonar S8544, S8541).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Change-Id: I46e6b4fc67db5f8c8eb25aaf727bade9aebf618d
Signed-off-by: Anil Belur <abelur@linuxfoundation.org>1 parent 6ec15af commit 53bef1b
1 file changed
Lines changed: 4 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
53 | 53 | | |
54 | 54 | | |
55 | 55 | | |
56 | | - | |
| 56 | + | |
| 57 | + | |
57 | 58 | | |
58 | 59 | | |
59 | 60 | | |
| |||
95 | 96 | | |
96 | 97 | | |
97 | 98 | | |
98 | | - | |
| 99 | + | |
| 100 | + | |
99 | 101 | | |
100 | 102 | | |
101 | 103 | | |
| |||
0 commit comments