Skip to content

Commit 4ad1f08

Browse files
[fix](build): YAML(copied from @RalphHightower/blog) (#637)
Signed-off-by: Ralph Hightower <[email protected]>
1 parent 560a520 commit 4ad1f08

File tree

1 file changed

+21
-4
lines changed

1 file changed

+21
-4
lines changed

.github/workflows/release-please.yml

Lines changed: 21 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,17 +5,34 @@ on:
55
- main
66

77
permissions:
8-
pull-requests: write
9-
10-
name: release-please
8+
actions: none
9+
attestations: none
10+
checks: none
11+
contents: none
12+
deployments: none
13+
id-token: none
14+
issues: none
15+
discussions: none
16+
packages: none
17+
pages: none
18+
pull-requests: none
19+
repository-projects: none
20+
security-events: none
21+
statuses: none
1122

1223
jobs:
1324
release-please:
1425
runs-on: ubuntu-latest
1526
steps:
16-
- uses: googleapis/[email protected]
27+
- name: Harden Runner
28+
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
29+
with:
30+
egress-policy: audit
31+
32+
- uses: googleapis/release-please-action@a02a34c4d625f9be7cb89156071d8567266a2445 # v4.2.0
1733
with:
1834
contents: write
35+
pull-requests: write
1936
# this assumes that you have created a personal access token
2037
# (PAT) and configured it as a GitHub action secret named
2138
# `MY_RELEASE_PLEASE_TOKEN` (this secret name is not important).

0 commit comments

Comments
 (0)