Skip to content

Commit d35c6b5

Browse files
authored
Merge pull request #6348 from alphagov/bk-add-permissions
Add explicit permissions to workflows
2 parents 07a5c93 + be37995 commit d35c6b5

File tree

5 files changed

+20
-0
lines changed

5 files changed

+20
-0
lines changed

.github/workflows/bundler-integrations.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,9 @@ jobs:
99
name: Test tree shaking
1010
runs-on: ubuntu-22.04
1111

12+
permissions:
13+
contents: read
14+
1215
env:
1316
PUPPETEER_SKIP_DOWNLOAD: true
1417

.github/workflows/sass.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,9 @@ on:
1111

1212
workflow_dispatch:
1313

14+
permissions:
15+
contents: read
16+
1417
concurrency:
1518
group: sass-${{ github.head_ref || github.run_id }}
1619
cancel-in-progress: true

.github/workflows/screenshots.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ on:
44
workflow_call:
55
workflow_dispatch:
66

7+
permissions:
8+
contents: read
9+
pull-requests: read
10+
711
concurrency:
812
group: screenshots-${{ github.head_ref || github.run_id }}
913
cancel-in-progress: true

.github/workflows/stats-comment.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ on:
44
workflow_call:
55
workflow_dispatch:
66

7+
permissions:
8+
contents: read
9+
pull-requests: write # For writing comments
10+
711
jobs:
812
generate-stats:
913
name: Generate stats

.github/workflows/tests.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ on:
1111

1212
workflow_dispatch:
1313

14+
permissions:
15+
contents: read
16+
pull-requests: read
17+
1418
concurrency:
1519
group: tests-${{ github.head_ref || github.run_id }}
1620
cancel-in-progress: true
@@ -313,6 +317,7 @@ jobs:
313317
needs: [install]
314318

315319
permissions:
320+
contents: read
316321
pull-requests: write
317322

318323
# Run existing "Diff changes to npm package" workflow
@@ -324,6 +329,7 @@ jobs:
324329
needs: [install]
325330

326331
permissions:
332+
contents: read
327333
pull-requests: write
328334

329335
# Run existing "Stats comment" workflow

0 commit comments

Comments
 (0)