Skip to content

Commit 8a383c6

Browse files
authored
Fix some Scorecard issues (#238)
1 parent 2177ba2 commit 8a383c6

File tree

7 files changed

+16
-9
lines changed

7 files changed

+16
-9
lines changed

.github/workflows/auto-update.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,8 @@ on:
1414
- main
1515
- release-*
1616

17-
permissions: {}
17+
permissions:
18+
contents: read
1819

1920
concurrency:
2021
group: ${{ github.workflow }}-${{ github.ref }}

.github/workflows/post-merge-adm-nbi.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@ on:
1313
- 'app-deployment-manager/api/nbi/**'
1414
workflow_dispatch:
1515

16-
permissions: {}
16+
permissions:
17+
contents: read
1718

1819
jobs:
1920
post-merge-pipeline:

.github/workflows/post-merge-adm.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@ on:
1313
- 'app-deployment-manager/**'
1414
workflow_dispatch:
1515

16-
permissions: {}
16+
permissions:
17+
contents: read
1718

1819
jobs:
1920
post-merge-pipeline:

.github/workflows/post-merge-arm.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@ on:
1313
- 'app-resource-manager/**'
1414
workflow_dispatch:
1515

16-
permissions: {}
16+
permissions:
17+
contents: read
1718

1819
jobs:
1920
post-merge-pipeline:

.github/workflows/post-merge-asp.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@ on:
1313
- 'app-service-proxy/**'
1414
workflow_dispatch:
1515

16-
permissions: {}
16+
permissions:
17+
contents: read
1718

1819
jobs:
1920
post-merge-pipeline:

.github/workflows/post-merge-interconnect.yaml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@ on:
1313
- 'app-interconnect/**'
1414
workflow_dispatch:
1515

16-
permissions: {}
16+
permissions:
17+
contents: read
1718

1819
jobs:
1920
post-merge-pipeline:

.github/workflows/post-merge-scorecard.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,11 @@ permissions:
1616
jobs:
1717
call-scorecard:
1818
permissions:
19-
contents: read
20-
security-events: write
19+
security-events: write # required for SARIF upload
2120
id-token: write
22-
uses: open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml@main
21+
contents: read
22+
23+
uses: open-edge-platform/orch-ci/.github/workflows/post-merge-scorecard.yml@490a8651344e504bba68a208b1104254046dacd5 # v0.1.65
2324
with:
2425
project_folder: "."
2526
secrets:

0 commit comments

Comments
 (0)