Skip to content

Commit 34bace1

Browse files
authored
refactor(ci): set permissions (#275)
1 parent 34db855 commit 34bace1

4 files changed

Lines changed: 25 additions & 0 deletions

File tree

.github/workflows/lint.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ on:
77
jobs:
88
lint:
99
runs-on: ubuntu-latest
10+
11+
permissions:
12+
contents: read
13+
1014
steps:
1115
- name: Checkout repository
1216
uses: actions/checkout@v4

.github/workflows/package.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,13 @@ on:
55
jobs:
66
package:
77
runs-on: ubuntu-latest
8+
9+
permissions:
10+
contents: write
11+
packages: write
12+
pull-requests: read
13+
id-token: write
14+
815
steps:
916
- name: Checkout repository
1017
uses: actions/checkout@v4

.github/workflows/release.yml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ on:
55
jobs:
66
test:
77
name: Test for release
8+
9+
permissions:
10+
contents: read
11+
812
if: startsWith(github.event.head_commit.message, '[release:minor]') ||
913
startsWith(github.event.head_commit.message, '[release:major]') ||
1014
startsWith(github.event.head_commit.message, '[release:patch]')
@@ -13,6 +17,12 @@ jobs:
1317
release:
1418
runs-on: ubuntu-latest
1519
needs: [test]
20+
21+
permissions:
22+
contents: write
23+
packages: write
24+
pull-requests: read
25+
1626
steps:
1727
- name: Checkout repository
1828
uses: actions/checkout@v4

.github/workflows/test.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,10 @@ on:
88
jobs:
99
test:
1010
runs-on: ubuntu-latest
11+
12+
permissions:
13+
contents: read
14+
1115
steps:
1216
- name: Checkout repository
1317
uses: actions/checkout@v4

0 commit comments

Comments
 (0)