Skip to content

Commit e7e29d5

Browse files
authored
Merge pull request #406 from crazy-max/gha-perms
ci: set contents read as default workflow permissions
2 parents cbfd3fa + 6ee51ce commit e7e29d5

File tree

5 files changed

+41
-0
lines changed

5 files changed

+41
-0
lines changed

.github/workflows/build.yml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
push:
913
branches:
@@ -143,6 +147,9 @@ jobs:
143147

144148
release:
145149
runs-on: ubuntu-latest
150+
permissions:
151+
# required to create GitHub release
152+
contents: write
146153
needs:
147154
- artifact
148155
- test
@@ -183,6 +190,11 @@ jobs:
183190

184191
image:
185192
runs-on: ubuntu-latest
193+
permissions:
194+
# same as global permissions
195+
contents: read
196+
# required to push to GHCR
197+
packages: write
186198
needs:
187199
- artifact
188200
- test

.github/workflows/codeql.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
push:
913
branches:
@@ -19,6 +23,11 @@ on:
1923
jobs:
2024
codeql:
2125
runs-on: ubuntu-latest
26+
permissions:
27+
# same as global permissions
28+
contents: read
29+
# required for code scanning
30+
security-events: write
2231
steps:
2332
-
2433
name: Checkout

.github/workflows/docs.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
workflow_dispatch:
913
push:
@@ -18,6 +22,9 @@ env:
1822
jobs:
1923
publish:
2024
runs-on: ubuntu-latest
25+
permissions:
26+
# required to push to gh-pages
27+
contents: write
2128
steps:
2229
-
2330
name: Checkout

.github/workflows/e2e.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
push:
913
branches:

.github/workflows/labels.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
push:
913
branches:
@@ -19,6 +23,11 @@ on:
1923
jobs:
2024
labeler:
2125
runs-on: ubuntu-latest
26+
permissions:
27+
# same as global permissions
28+
contents: read
29+
# required to update labels
30+
issues: write
2231
steps:
2332
-
2433
name: Checkout

0 commit comments

Comments
 (0)