Skip to content
Open
3 changes: 3 additions & 0 deletions .github/workflows/build-all-distros-nightly.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
- cron: '0 9 * * 1-5'
workflow_dispatch: {}

permissions:
contents: read

jobs:
build-all-distros:
name: build all distros
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/docker-publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
release:
types: [published]

permissions:
contents: read

jobs:
build-and-push-to-registry:
name: Build and push container image
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/homebrew-update.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
release:
types: [published]

permissions:
issues: write

jobs:
notify-homebrew:
runs-on: ubuntu-latest
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/pr-labels.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
pull_request:
types: [labeled, unlabeled, opened, edited, synchronize]

permissions:
contents: read

jobs:
enforce-kind:
name: Enforce a valid PR category
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/publish-docs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ name: Publish docs
on:
release:
types: [published]
permissions:
contents: read

jobs:
publish-docs:
name: Publish docs to Netlify
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/publish-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,9 @@ on:
customToken:
required: true

permissions:
contents: write

jobs:
publish-release:
name: ${{ inputs.isReleaseCandidate && 'prerelease' || 'release' }}
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/release-candidate.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ name: Trigger Release Candidate
on:
workflow_dispatch: {}

permissions:
contents: write
pull-requests: write

jobs:
rc:
name: Push release candidate tag
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/release-merge.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@ on:
env:
VERSION_FILE: pkg/version/release.go
DEFAULT_BRANCH: main
permissions:
contents: write
pull-requests: write

jobs:
merge_release:
name: Merge release
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ name: Trigger Release
on:
workflow_dispatch: {}

permissions:
contents: write
pull-requests: write

jobs:
rc:
name: Push release tag
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/test-and-build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
pull_request: {}
workflow_call: {}

permissions:
contents: read

jobs:
unit-test:
name: Unit tests
Expand Down
Loading