Skip to content

Commit 07f7631

Browse files
committed
ci: Set run-level permissions
1 parent 3d0624c commit 07f7631

File tree

2 files changed

+14
-8
lines changed

2 files changed

+14
-8
lines changed

.github/workflows/build.yml

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,14 @@ on:
55
- main
66
pull_request:
77

8-
permissions:
9-
contents: read
10-
checks: write
11-
statuses: write
8+
permissions: read-all
129

1310
jobs:
1411
compile:
12+
permissions:
13+
contents: read
14+
checks: write
15+
statuses: write
1516
runs-on: ${{ matrix.os }}
1617
strategy:
1718
fail-fast: false
@@ -31,6 +32,10 @@ jobs:
3132
run: mvn -e --batch-mode compile -T 1C
3233

3334
verify:
35+
permissions:
36+
contents: read
37+
checks: write
38+
statuses: write
3439
runs-on: ${{ matrix.os }}
3540
strategy:
3641
fail-fast: false
@@ -56,6 +61,6 @@ jobs:
5661
VONAGE_PRIVATE_KEY_PATH: src/test/resources/com/vonage/client/kt/application_key
5762
run: mvn -e --batch-mode clean verify -T 1C
5863
- name: Run Codecov
59-
uses: codecov/codecov-action@v4
64+
uses: codecov/codecov-action@288befbd1044bd1756afb0bdae077549e0ddb31f
6065
with:
6166
token: ${{ secrets.CODECOV_TOKEN }}

.github/workflows/publish.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,13 @@ on:
33
release:
44
types: [published]
55

6-
permissions:
7-
contents: read
8-
packages: write
6+
permissions: read-all
97

108
jobs:
119
publish:
10+
permissions:
11+
contents: read
12+
packages: write
1213
runs-on: ubuntu-latest
1314
steps:
1415
- name: Checkout the repo

0 commit comments

Comments
 (0)