Skip to content

Commit 23fc5e0

Browse files
ci: add minimum GitHub token permissions for workflows (#1792)
Signed-off-by: Varun Sharma <[email protected]>
1 parent 93d1913 commit 23fc5e0

File tree

4 files changed

+23
-0
lines changed

4 files changed

+23
-0
lines changed

.github/workflows/labeler.yml

+6
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,14 @@ name: "Pull Request Labeler"
22
on:
33
- pull_request_target
44

5+
permissions:
6+
contents: read
7+
58
jobs:
69
triage:
10+
permissions:
11+
contents: read # for actions/labeler to determine modified files
12+
pull-requests: write # for actions/labeler to add labels to PRs
713
runs-on: ubuntu-latest
814
steps:
915
- uses: actions/labeler@v4

.github/workflows/size-labeler.yml

+5
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,13 @@ name: size-labeler
44

55
on: [pull_request_target]
66

7+
permissions:
8+
contents: read
9+
710
jobs:
811
size-labeler:
12+
permissions:
13+
pull-requests: write # for codelytv/pr-size-labeler to add labels & comment on PRs
914
runs-on: ubuntu-latest
1015
name: Label the PR size
1116
steps:

.github/workflows/stale.yml

+6
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,15 @@ on:
44
schedule:
55
- cron: "0 0 * * *"
66

7+
permissions:
8+
contents: read
9+
710
jobs:
811
stale:
912

13+
permissions:
14+
issues: write # for actions/stale to close stale issues
15+
pull-requests: write # for actions/stale to close stale PRs
1016
runs-on: ubuntu-latest
1117

1218
steps:

.github/workflows/test.yml

+6
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ on:
88
env:
99
GO111MODULE: on
1010

11+
permissions:
12+
contents: read
13+
1114
jobs:
1215

1316

@@ -30,6 +33,9 @@ jobs:
3033
3134
3235
golangci-lint:
36+
permissions:
37+
contents: read # for actions/checkout to fetch code
38+
pull-requests: read # for golangci/golangci-lint-action to fetch pull requests
3339
runs-on: ubuntu-latest
3440
steps:
3541

0 commit comments

Comments
 (0)