[StepSecurity] ci: Harden GitHub Actions (#27202)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
This commit is contained in:
StepSecurity Bot
2026-04-07 20:29:52 +00:00
committed by GitHub
parent 22f62e859d
commit 601f0167e0
3 changed files with 9 additions and 0 deletions
@@ -10,6 +10,9 @@ on:
paths:
- ".github/workflows/copilot-setup-steps.yml"
permissions:
contents: read
jobs:
# The job MUST be called `copilot-setup-steps` or it will not be picked up by Copilot.
# See https://docs.github.com/en/copilot/customizing-copilot/customizing-the-development-environment-for-copilot-coding-agent
@@ -13,6 +13,9 @@ env:
SYSTEM_ARTIFACTSDIRECTORY: ${{ github.workspace }}/artifacts
BUILD_ARTIFACTSTAGINGDIRECTORY: ${{ github.workspace }}/artifacts
permissions:
contents: read
jobs:
package:
name: ${{ matrix.architecture }} - ${{ matrix.channel }}
+3
View File
@@ -14,6 +14,9 @@ on:
required: false
default: testResults-xunit
permissions:
contents: read
jobs:
xunit:
name: Run xUnit Tests