Skip to content

Commit 349a2ab

Browse files
committed
ci: improve fine grained permissions
Signed-off-by: Emilien Escalle <[email protected]>
1 parent 2183dac commit 349a2ab

File tree

3 files changed

+13
-14
lines changed

3 files changed

+13
-14
lines changed

.github/workflows/__greetings.yml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,12 @@ on:
66
pull_request_target:
77
branches: [main]
88

9-
permissions:
10-
contents: read
11-
issues: write
12-
pull-requests: write
9+
permissions: {}
1310

1411
jobs:
1512
greetings:
1613
uses: hoverkraft-tech/ci-github-common/.github/workflows/greetings.yml@c314229c3ca6914f7023ffca7afc26753ab99b41 # 0.30.1
14+
permissions:
15+
contents: read
16+
issues: write
17+
pull-requests: write

.github/workflows/__need-fix-to-issue.yml

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -14,17 +14,14 @@ on:
1414
description: "By default, the commit entered above is compared to the one directly before it; to go back further, enter an earlier SHA here"
1515
required: false
1616

17-
permissions:
18-
contents: read
19-
issues: write
20-
21-
concurrency:
22-
group: ${{ github.workflow }}-${{ github.ref }}
23-
cancel-in-progress: true
17+
permissions: {}
2418

2519
jobs:
2620
main:
2721
uses: hoverkraft-tech/ci-github-common/.github/workflows/need-fix-to-issue.yml@c314229c3ca6914f7023ffca7afc26753ab99b41 # 0.30.1
22+
permissions:
23+
contents: read
24+
issues: write
2825
with:
2926
manual-commit-ref: ${{ inputs.manual-commit-ref }}
3027
manual-base-ref: ${{ inputs.manual-base-ref }}

.github/workflows/__stale.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,11 @@ on:
44
schedule:
55
- cron: "30 1 * * *"
66

7-
permissions:
8-
issues: write
9-
pull-requests: write
7+
permissions: {}
108

119
jobs:
1210
main:
1311
uses: hoverkraft-tech/ci-github-common/.github/workflows/stale.yml@c314229c3ca6914f7023ffca7afc26753ab99b41 # 0.30.1
12+
permissions:
13+
issues: write
14+
pull-requests: write

0 commit comments

Comments
 (0)