Skip to content

Commit dcdfa3f

Browse files
authored
ci: specify permissions that workflows pass to jobs/actions (#201)
Signed-off-by: Charles Moore <[email protected]>
1 parent 5c8c267 commit dcdfa3f

File tree

4 files changed

+12
-0
lines changed

4 files changed

+12
-0
lines changed

.github/workflows/codeql.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,3 +12,5 @@ jobs:
1212
Analysis:
1313
name: Analysis
1414
uses: OpenJobDescription/.github/.github/workflows/reusable_codeql.yml@mainline
15+
permissions:
16+
security-events: write

.github/workflows/release_bump.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,9 @@ jobs:
2020
Bump:
2121
name: Version Bump
2222
uses: OpenJobDescription/.github/.github/workflows/reusable_bump.yml@mainline
23+
permissions:
24+
contents: write
25+
pull-requests: write
2326
secrets: inherit
2427
with:
2528
force_version_bump: ${{ inputs.force_version_bump }}

.github/workflows/responded.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,3 +6,6 @@ on:
66
jobs:
77
check-for-response:
88
uses: OpenJobDescription/.github/.github/workflows/reusable_responded.yml@mainline
9+
permissions:
10+
issues: write
11+
pull-requests: write

.github/workflows/stale_prs_and_issues.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,3 +7,7 @@ on:
77
jobs:
88
check-for-stales:
99
uses: OpenJobDescription/.github/.github/workflows/reusable_stale_prs_and_issues.yml@mainline
10+
permissions:
11+
contents: read
12+
issues: write
13+
pull-requests: write

0 commit comments

Comments
 (0)