Skip to content

Commit c760403

Browse files
authored
chore: template-oss-apply for workflow permissions (#784)
1 parent c99f336 commit c760403

File tree

7 files changed

+21
-0
lines changed

7 files changed

+21
-0
lines changed

.github/workflows/audit.yml

+3
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ on:
88
# "At 08:00 UTC (01:00 PT) on Monday" https://crontab.guru/#0_8_*_*_1
99
- cron: "0 8 * * 1"
1010

11+
permissions:
12+
contents: read
13+
1114
jobs:
1215
audit:
1316
name: Audit Dependencies

.github/workflows/ci-release.yml

+4
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,10 @@ on:
1818
required: true
1919
type: string
2020

21+
permissions:
22+
contents: read
23+
checks: write
24+
2125
jobs:
2226
lint-all:
2327
name: Lint All

.github/workflows/ci.yml

+3
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,9 @@ on:
1313
# "At 09:00 UTC (02:00 PT) on Monday" https://crontab.guru/#0_9_*_*_1
1414
- cron: "0 9 * * 1"
1515

16+
permissions:
17+
contents: read
18+
1619
jobs:
1720
lint:
1821
name: Lint

.github/workflows/codeql-analysis.yml

+3
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@ on:
1515
# "At 10:00 UTC (03:00 PT) on Monday" https://crontab.guru/#0_10_*_*_1
1616
- cron: "0 10 * * 1"
1717

18+
permissions:
19+
contents: read
20+
1821
jobs:
1922
analyze:
2023
name: Analyze

.github/workflows/pull-request.yml

+3
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,9 @@ on:
1010
- edited
1111
- synchronize
1212

13+
permissions:
14+
contents: read
15+
1316
jobs:
1417
commitlint:
1518
name: Lint Commits

.github/workflows/release-integration.yml

+4
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,10 @@ on:
1919
PUBLISH_TOKEN:
2020
required: true
2121

22+
permissions:
23+
contents: read
24+
id-token: write
25+
2226
jobs:
2327
publish:
2428
name: Publish

.github/workflows/release.yml

+1
Original file line numberDiff line numberDiff line change
@@ -245,6 +245,7 @@ jobs:
245245
if: needs.release.outputs.releases
246246
uses: ./.github/workflows/release-integration.yml
247247
permissions:
248+
contents: read
248249
id-token: write
249250
secrets:
250251
PUBLISH_TOKEN: ${{ secrets.PUBLISH_TOKEN }}

0 commit comments

Comments
 (0)