Skip to content

Commit 66d3ff2

Browse files
GitHub workflows: explicit permissions, checkout v6, sdk_ci sync
1 parent 829bb49 commit 66d3ff2

File tree

3 files changed

+15
-2
lines changed

3 files changed

+15
-2
lines changed

.github/workflows/auto_assign_ci.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ on:
77
- synchronize
88
- reopened
99

10+
permissions:
11+
contents: read
12+
pull-requests: write
13+
1014
jobs:
1115
add-assignee:
1216
name: Auto assign (me only)

.github/workflows/codeql.yml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,12 @@ on:
1919
schedule:
2020
- cron: '40 8 * * 3'
2121

22+
permissions:
23+
security-events: write
24+
packages: read
25+
actions: read
26+
contents: read
27+
2228
jobs:
2329
analyze:
2430
name: Analyze (${{ matrix.language }})
@@ -55,7 +61,7 @@ jobs:
5561
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
5662
steps:
5763
- name: Checkout repository
58-
uses: actions/checkout@v4
64+
uses: actions/checkout@v6
5965

6066
# Add any setup steps before running the `github/codeql-action/init` action.
6167
# This includes steps like installing compilers or runtimes (`actions/setup-node`

.github/workflows/sdk_ci.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,12 +7,15 @@ on:
77
push:
88
branches: [main, master]
99

10+
permissions:
11+
contents: read
12+
1013
jobs:
1114
test:
1215
name: Test
1316
runs-on: ubuntu-latest
1417
steps:
15-
- uses: actions/checkout@v4
18+
- uses: actions/checkout@v6
1619

1720
- name: Set up Go
1821
uses: actions/setup-go@v5

0 commit comments

Comments
 (0)