Skip to content

Commit b3d1490

Browse files
authored
Merge pull request #235 from crazy-max/gha-perms
ci: set contents read as default workflow permissions
2 parents fbf0a4f + 67e1909 commit b3d1490

File tree

5 files changed

+29
-2
lines changed

5 files changed

+29
-2
lines changed

.github/workflows/ci.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
schedule:
913
- cron: '0 10 * * *'
@@ -16,6 +20,9 @@ on:
1620
jobs:
1721
ci:
1822
runs-on: ubuntu-latest
23+
permissions:
24+
# required to push to gh-pages
25+
contents: write
1926
strategy:
2027
fail-fast: false
2128
matrix:

.github/workflows/cleanup.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
workflow_dispatch:
913
schedule:
@@ -12,6 +16,9 @@ on:
1216
jobs:
1317
branches:
1418
runs-on: ubuntu-latest
19+
permissions:
20+
# required to remove git branch
21+
contents: write
1522
strategy:
1623
fail-fast: false
1724
matrix:

.github/workflows/labels.yml

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,14 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
push:
913
branches:
10-
- 'dev'
14+
- 'master'
1115
paths:
1216
- '.github/labels.yml'
1317
- '.github/workflows/labels.yml'
@@ -19,6 +23,11 @@ on:
1923
jobs:
2024
labeler:
2125
runs-on: ubuntu-latest
26+
permissions:
27+
# same as global permissions
28+
contents: read
29+
# required to update labels
30+
issues: write
2231
steps:
2332
-
2433
name: Checkout

.github/workflows/validate.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,10 @@ concurrency:
44
group: ${{ github.workflow }}-${{ github.ref }}
55
cancel-in-progress: true
66

7+
# https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
8+
permissions:
9+
contents: read
10+
711
on:
812
push:
913
branches:

LICENSE

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
MIT License
22

3-
Copyright (c) 2019-2024 CrazyMax
3+
Copyright (c) 2019-2025 CrazyMax
44

55
Permission is hereby granted, free of charge, to any person obtaining a copy
66
of this software and associated documentation files (the "Software"), to deal

0 commit comments

Comments
 (0)