Skip to content

Commit 52360b0

Browse files
committed
1 parent bf98127 commit 52360b0

File tree

1 file changed

+12
-5
lines changed

1 file changed

+12
-5
lines changed

.github/workflows/ci-cd.yml

Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,17 +15,21 @@ concurrency:
1515
cancel-in-progress: true
1616

1717
permissions:
18-
contents: write # publish a GitHub release
19-
pages: write # deploy to GitHub Pages
20-
issues: write # comment on released issues
21-
pull-requests: write # comment on released pull requests
22-
id-token: write # allows GHA to generate OIDC tokens
18+
contents: read # checkout
2319

2420
jobs:
2521
build-and-deploy:
2622
runs-on: ubuntu-latest
23+
permissions:
24+
contents: write # publish a GitHub release
25+
id-token: write # allows GHA to generate OIDC tokens
26+
issues: write # comment on released issues
27+
pages: write # deploy to GitHub Pages
28+
pull-requests: write # comment on released pull requests
2729
steps:
2830
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
31+
with:
32+
persist-credentials: false # automatic GITHUB_TOKEN would interfere with custom one in semantic-release step
2933

3034
- uses: actions/setup-node@1a4442cacd436585916779262731d5b162bc6ec7 # v3
3135
with:
@@ -47,6 +51,9 @@ jobs:
4751
- name: Install dependencies
4852
run: npm ci
4953

54+
- name: Audit npm signatures
55+
run: npm audit signatures
56+
5057
- name: Setup & Test
5158
run: |
5259
mkdir -p ./test/results

0 commit comments

Comments
 (0)