ci: tighten codeql and labeler even more
authorEvgeny Vereshchagin <evvers@ya.ru>
Sun, 14 Nov 2021 09:41:42 +0000 (09:41 +0000)
committerEvgeny Vereshchagin <evvers@ya.ru>
Sun, 14 Nov 2021 10:51:07 +0000 (10:51 +0000)
commit510afa460acad51a05e627f61d62a33f066b78da
tree56e3b20896538e2b2ad40b1e5c0711fc6e34fd69
parentb3a1fb795a75a82f3be1325031872dfe61cc2593
ci: tighten codeql and labeler even more

by moving the read permissions to the top level and
granting additional permissions to the specific jobs.
It should help to prevent new jobs that could be added
there eventually from having write access to resources they
most likely would never need.
.github/workflows/codeql-analysis.yml
.github/workflows/labeler.yml