Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add minimum GitHub token permissions for workflows #7540

Closed
joycebrum opened this issue Mar 14, 2023 · 1 comment · Fixed by #7541
Closed

Add minimum GitHub token permissions for workflows #7540

joycebrum opened this issue Mar 14, 2023 · 1 comment · Fixed by #7541
Labels

Comments

@joycebrum
Copy link
Contributor

@akarnokd can I bring up this topic (#7469) again and perhaps suggest a PR with the permission that were missing in this one? It is really a relevant topic on supply-chain security that prevents any threats and attacks.

But before I would like to understand what didn't work on https://github.com/ReactiveX/RxJava/actions/runs/2343714818/jobs/3517587271 because for me it shows as success.

Looking into gradle_snapshot.yml and gradle_release.yml I've noticed that perhaps the permission that were missing was a contents: write to run this command

git push --quiet --set-upstream origin-pages gh-pages

Let me know if a PR is welcome and I'll try testing it before submit it, although I think it will be difficult considering sonatype access used.

@akarnokd
Copy link
Member

The build doesn't fail if it can't push the javadoc back.

Alright, let's try your suggestion via PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants