Skip to content

Commit 354853d

Browse files
committed
Explicit workflow permissions
1 parent 6767b0e commit 354853d

File tree

3 files changed

+40
-0
lines changed

3 files changed

+40
-0
lines changed

.github/workflows/build.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,19 @@ on:
55
- main
66
pull_request:
77

8+
permissions:
9+
actions: write
10+
checks: write
11+
contents: read
12+
deployments: read
13+
issues: write
14+
discussions: read
15+
packages: none
16+
pages: read
17+
pull-requests: write
18+
security-events: write
19+
statuses: write
20+
821
jobs:
922
build_only:
1023
runs-on: ${{ matrix.os }}

.github/workflows/metrics.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,19 @@ on:
44
schedule:
55
- cron: "0 0 * * *"
66

7+
permissions:
8+
actions: write
9+
checks: read
10+
contents: read
11+
deployments: read
12+
issues: read
13+
discussions: read
14+
packages: none
15+
pages: read
16+
pull-requests: read
17+
security-events: read
18+
statuses: write
19+
720
jobs:
821
recordMetrics:
922
runs-on: ubuntu-latest

.github/workflows/publish.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,20 @@ name: Publish to Nexus
22
on:
33
release:
44
types: [published]
5+
6+
permissions:
7+
actions: write
8+
checks: write
9+
contents: write
10+
deployments: read
11+
issues: write
12+
discussions: write
13+
packages: write
14+
pages: write
15+
pull-requests: write
16+
security-events: write
17+
statuses: write
18+
519
jobs:
620
build:
721
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)