Skip to content

Commit cc7b9ac

Browse files
authored
Merge pull request #5123 from zhzhuang-zju/miniumPermissions
set Minimum GITHUB_TOKEN permissions to github workflow
2 parents 7aaea78 + b20e002 commit cc7b9ac

File tree

6 files changed

+20
-0
lines changed

6 files changed

+20
-0
lines changed

.github/workflows/dockerhub-latest-image.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ on:
33
push:
44
branches:
55
- master
6+
permissions:
7+
contents: read
68
jobs:
79
publish-image-to-dockerhub:
810
name: publish to DockerHub

.github/workflows/dockerhub-released-chart.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ on:
33
release:
44
types:
55
- published
6+
permissions:
7+
contents: read
68
jobs:
79
publish-chart-to-dockerhub:
810
name: publish to DockerHub

.github/workflows/dockerhub-released-image.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ on:
33
release:
44
types:
55
- published
6+
permissions:
7+
contents: read
68
jobs:
79
publish-image-to-dockerhub:
810
name: publish to DockerHub

.github/workflows/release.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,12 @@ on:
33
types:
44
- published
55
name: Build Release
6+
permissions:
7+
contents: read
68
jobs:
79
release-assests:
10+
permissions:
11+
contents: write # for softprops/action-gh-release to create GitHub release
812
name: release kubectl-karmada
913
runs-on: ubuntu-22.04
1014
strategy:
@@ -41,6 +45,8 @@ jobs:
4145
_output/release/${{ matrix.target }}-${{ matrix.os }}-${{ matrix.arch }}.tgz
4246
_output/release/${{ matrix.target }}-${{ matrix.os }}-${{ matrix.arch }}.tgz.sha256
4347
release-crds-assests:
48+
permissions:
49+
contents: write # for softprops/action-gh-release to create GitHub release
4450
name: release crds
4551
runs-on: ubuntu-22.04
4652
steps:
@@ -61,6 +67,8 @@ jobs:
6167
files: |
6268
crds.tar.gz
6369
release-charts:
70+
permissions:
71+
contents: write # for softprops/action-gh-release to create GitHub release
6472
name: Release charts
6573
runs-on: ubuntu-22.04
6674
steps:
@@ -79,6 +87,8 @@ jobs:
7987
_output/charts/karmada-operator-chart-${{ github.ref_name }}.tgz
8088
_output/charts/karmada-operator-chart-${{ github.ref_name }}.tgz.sha256
8189
sbom-assests:
90+
permissions:
91+
contents: write # for softprops/action-gh-release to create GitHub release
8292
name: Release sbom
8393
runs-on: ubuntu-22.04
8494
steps:

.github/workflows/swr-latest-image.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ on:
33
push:
44
branches:
55
- master
6+
permissions:
7+
contents: read
68
jobs:
79
publish-image:
810
name: publish images

.github/workflows/swr-released-image.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ on:
33
release:
44
types:
55
- published
6+
permissions:
7+
contents: read
68
jobs:
79
release-image:
810
name: release images

0 commit comments

Comments
 (0)