Skip to content

Commit e97ee25

Browse files
Add minimum token permissions for all github workflow files (#6950)
See open-telemetry/sig-security#148 for details. Co-authored-by: otelbot <[email protected]>
1 parent 86640ce commit e97ee25

File tree

5 files changed

+10
-5
lines changed

5 files changed

+10
-5
lines changed

.github/workflows/benchmark.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,8 @@ env:
1212
DEFAULT_GO_VERSION: "~1.24.0"
1313
jobs:
1414
benchmark:
15+
permissions:
16+
contents: write # required for pushing to gh-pages branch
1517
name: Benchmarks
1618
runs-on: equinix-bare-metal
1719
steps:

.github/workflows/close-stale.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,13 @@ on:
55
- cron: "8 5 * * *" # arbitrary time not to DDOS GitHub
66

77
permissions:
8-
issues: write
9-
pull-requests: write
8+
contents: read
9+
1010
jobs:
1111
stale:
12+
permissions:
13+
issues: write
14+
pull-requests: write
1215
runs-on: ubuntu-latest
1316
steps:
1417
- uses: actions/stale@5bef64f19d7facfb25b37b414482c7164d639639 # v9.1.0

.github/workflows/links-fail-fast.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,6 @@ jobs:
3636
runs-on: ubuntu-latest
3737
needs: changedfiles
3838
if: ${{needs.changedfiles.outputs.files}}
39-
permissions:
40-
contents: read
4139
steps:
4240
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
4341

.github/workflows/links.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
check-links:
1515
runs-on: ubuntu-latest
1616
permissions:
17-
contents: read
17+
issues: write # required for creating issues from link checker reports
1818
steps:
1919
- name: Checkout Repo
2020
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

.github/workflows/markdown.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,8 @@ permissions: read-all
1212

1313
jobs:
1414
lint-markdown:
15+
permissions:
16+
issues: write # required for creating issues from markdown lint reports
1517
runs-on: ubuntu-latest
1618
steps:
1719
- name: Checkout Repo

0 commit comments

Comments
 (0)