Skip to content

Conversation

@MartinWheelerMT
Copy link
Collaborator

  • Restrict permissions per job to ensure that only the least required permissions are granted in build workflow.
  • Use SHAs for GitHub Actions actions instead of versions to ensure we have control over exactly which version is being used in build workflow.
  • Change permissions for Create Build ID Comment to only allow write on pull requests.

* Restrict permissions per job to ensure that only the least required permissions are granted in `build` workflow.
* Use SHAs for GitHub Actions `actions` instead of versions to ensure we have control over exactly which version is being used in `build` workflow.
* Change permissions for `Create Build ID Comment` to only allow `write` on pull requests.
@MartinWheelerMT MartinWheelerMT force-pushed the niad-3331-nhs-best-practice-for-github-actions branch from ad0d792 to 89d3bfd Compare May 28, 2025 14:36
@github-actions
Copy link

github-actions bot commented May 28, 2025

Images built and published to ECR using a Build Id of PR-87-7e9cea4

@Alex-Nita Alex-Nita self-requested a review May 28, 2025 15:51
@MartinWheelerMT MartinWheelerMT merged commit b760f94 into main Jun 3, 2025
8 checks passed
@MartinWheelerMT MartinWheelerMT deleted the niad-3331-nhs-best-practice-for-github-actions branch June 3, 2025 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants