Skip to content

Commit cd43504

Browse files
authored
Standardize permissions with other workflows (#17)
1 parent edb8fe1 commit cd43504

3 files changed

Lines changed: 11 additions & 13 deletions

File tree

.github/workflows/draft-release.yml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,12 @@ on:
1313
- 'minor'
1414
- 'patch'
1515

16-
permissions:
17-
contents: 'read'
18-
pull-requests: 'write'
19-
2016
jobs:
2117
draft-release:
2218
uses: 'google-github-actions/.github/.github/workflows/draft-release.yml@v3' # ratchet:exclude
19+
permissions:
20+
contents: 'read'
21+
pull-requests: 'write'
2322
with:
2423
version_strategy: '${{ github.event.inputs.version_strategy }}'
2524
secrets:

.github/workflows/publish.yml

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,14 +6,13 @@ on:
66
types:
77
- 'published'
88

9-
permissions:
10-
contents: 'read'
11-
id-token: 'write'
12-
packages: 'write'
13-
149
jobs:
1510
publish:
1611
runs-on: 'ubuntu-latest'
12+
permissions:
13+
contents: 'read'
14+
id-token: 'write'
15+
packages: 'write'
1716

1817
steps:
1918
- name: 'Checkout'

.github/workflows/release.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,12 +6,12 @@ on:
66
- 'main'
77
- 'release/**/*'
88

9-
permissions:
10-
contents: 'read'
11-
packages: 'write'
12-
139
jobs:
1410
release:
1511
uses: 'google-github-actions/.github/.github/workflows/release.yml@v3' # ratchet:exclude
12+
permissions:
13+
attestations: 'write'
14+
contents: 'write'
15+
packages: 'write'
1616
secrets:
1717
ACTIONS_BOT_TOKEN: '${{ secrets.ACTIONS_BOT_TOKEN }}'

0 commit comments

Comments
 (0)