Skip to content

Commit 4d3aa8b

Browse files
committed
ci: update ci permission and limit their environment
1. check checksum 2. merge master to dev
1 parent 7bb60a1 commit 4d3aa8b

File tree

2 files changed

+7
-5
lines changed

2 files changed

+7
-5
lines changed

.github/workflows/check_checksums.yml

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,16 +8,16 @@ jobs:
88
compare:
99
name: Compare checksums
1010
runs-on: macos-latest
11+
environment: Release
1112
permissions:
12-
contents: read
13-
actions: read
13+
contents: write # to append checksum for each commit
14+
actions: read # to read artifacts
1415
steps:
1516
- name: Checkout
1617
uses: actions/checkout@v4
1718

1819
- name: Generate checksums from artifacts
19-
run:
20-
ruby ./scripts/release-checksums.rb ${{ github.event.release.tag_name }} | tee generated_checksums.txt
20+
run: ruby ./scripts/release-checksums.rb ${{ github.event.release.tag_name }} | tee generated_checksums.txt
2121

2222
- name: Fetch checksums from release note
2323
run: |
@@ -39,4 +39,3 @@ jobs:
3939
- uses: peter-evans/commit-comment@v3
4040
with:
4141
body: ${{ steps.comment_body.outputs.body }}
42-

.github/workflows/merge_released_into_develop.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,9 @@ jobs:
99
merge-to-dev:
1010
name: Merge into develop
1111
runs-on: ubuntu-latest
12+
environment: Release
13+
permissions:
14+
pull-requests: write
1215
steps:
1316
- uses: actions/checkout@master
1417
- name: Request

0 commit comments

Comments
 (0)