From adc4fe5bff22821be67268e4c4026b4becd14204 Mon Sep 17 00:00:00 2001 From: Frazer Smith Date: Tue, 8 Nov 2022 10:08:23 +0000 Subject: [PATCH] ci: remove git credentials after checkout --- .github/workflows/ci.yml | 2 ++ .github/workflows/codeql-analysis.yml | 2 ++ .github/workflows/depsreview.yaml | 2 ++ 3 files changed, 6 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3b2814d0d9..fd9a278676 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,6 +19,8 @@ jobs: steps: - uses: actions/checkout@v3 + with: + persist-credentials: false - name: Setup node uses: actions/setup-node@v3 with: diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index cc6b8aeed3..1c267c3107 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -25,6 +25,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@v3 + with: + persist-credentials: false # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/depsreview.yaml b/.github/workflows/depsreview.yaml index a25de591ba..20c09f22d5 100644 --- a/.github/workflows/depsreview.yaml +++ b/.github/workflows/depsreview.yaml @@ -10,5 +10,7 @@ jobs: steps: - name: 'Checkout Repository' uses: actions/checkout@v3 + with: + persist-credentials: false - name: 'Dependency Review' uses: actions/dependency-review-action@v2