Skip to content

Commit 8780d3d

Browse files
authored
fix gha permissions (#411)
Signed-off-by: Kenny Leung <kleung@chainguard.dev>
1 parent c7a225c commit 8780d3d

File tree

6 files changed

+30
-0
lines changed

6 files changed

+30
-0
lines changed

.github/workflows/actionlint.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,15 @@ on:
77
pull_request:
88
branches: [ 'main', 'release-*' ]
99

10+
permissions: {}
11+
1012
jobs:
1113

1214
action-lint:
1315
name: Action lint
1416
runs-on: ubuntu-latest
17+
permissions:
18+
contents: read
1519

1620
steps:
1721
- name: Check out code

.github/workflows/boilerplate.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,15 @@ on:
77
pull_request:
88
branches: [ 'main', 'release-*' ]
99

10+
permissions: {}
11+
1012
jobs:
1113

1214
check:
1315
name: Boilerplate Check
1416
runs-on: ubuntu-latest
17+
permissions:
18+
contents: read
1519
strategy:
1620
fail-fast: false # Keep running if one leg fails.
1721
matrix:

.github/workflows/donotsubmit.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,15 @@ on:
77
pull_request:
88
branches: [ 'main', 'release-*' ]
99

10+
permissions: {}
11+
1012
jobs:
1113

1214
donotsubmit:
1315
name: Do Not Submit
1416
runs-on: ubuntu-latest
17+
permissions:
18+
contents: read
1519

1620
steps:
1721
- name: Check out code

.github/workflows/go-test.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,10 +9,14 @@ on:
99
push:
1010
branches: [ 'main', 'release-*' ]
1111

12+
permissions: {}
13+
1214
jobs:
1315

1416
test:
1517
runs-on: ubuntu-latest
18+
permissions:
19+
contents: read
1620
steps:
1721
- name: Check out code onto GOPATH
1822
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

.github/workflows/style.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,11 +9,15 @@ on:
99
push:
1010
branches: [ 'main', 'release-*' ]
1111

12+
permissions: {}
13+
1214
jobs:
1315

1416
gofmt:
1517
name: check gofmt
1618
runs-on: ubuntu-latest
19+
permissions:
20+
contents: read
1721
steps:
1822
- name: Check out code
1923
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
@@ -31,6 +35,8 @@ jobs:
3135
goimports:
3236
name: check goimports
3337
runs-on: ubuntu-latest
38+
permissions:
39+
contents: read
3440
steps:
3541
- name: Check out code
3642
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
@@ -46,6 +52,8 @@ jobs:
4652
golangci-lint:
4753
name: golangci-lint
4854
runs-on: ubuntu-latest
55+
permissions:
56+
contents: read
4957

5058
steps:
5159
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
@@ -67,6 +75,8 @@ jobs:
6775
lint:
6876
name: Lint
6977
runs-on: ubuntu-latest
78+
permissions:
79+
contents: read
7080

7181
steps:
7282
- name: Check out code

.github/workflows/verify.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,11 +9,15 @@ on:
99
push:
1010
branches: [ 'main', 'release-*' ]
1111

12+
permissions: {}
13+
1214
jobs:
1315

1416
verify:
1517
name: Verify Codegen
1618
runs-on: ubuntu-latest
19+
permissions:
20+
contents: read
1721

1822
env:
1923
GOPATH: ${{ github.workspace }}

0 commit comments

Comments
 (0)