Skip to content

Commit f16febc

Browse files
ci(github): set permissions in workflows
1 parent 7ee304b commit f16febc

File tree

7 files changed

+30
-4
lines changed

7 files changed

+30
-4
lines changed

.github/workflows/assign-reviewer.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: Assign Reviewer
22
on: pull_request_target
33

4+
permissions:
5+
pull-requests: write
6+
47
jobs:
58
assign-reviewer:
69
runs-on: ubuntu-latest

.github/workflows/build.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: build
22
on: [push, pull_request]
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
build:
69
runs-on: ubuntu-latest

.github/workflows/commitlint.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: commitlint
22
on: [push, pull_request]
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
commitlint:
69
runs-on: ubuntu-latest

.github/workflows/lint.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: lint
22
on: [push, pull_request]
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
lint:
69
runs-on: ubuntu-latest

.github/workflows/release-please.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,9 @@ jobs:
99
runs-on: ubuntu-latest
1010
outputs:
1111
release_created: ${{ steps.release.outputs.release_created }}
12+
permissions:
13+
contents: write
14+
pull-requests: write
1215

1316
steps:
1417
- name: Release Please
@@ -19,11 +22,11 @@ jobs:
1922

2023
publish:
2124
runs-on: ubuntu-latest
25+
needs: release-please
26+
if: ${{ needs.release-please.outputs.release_created }}
2227
permissions:
2328
contents: read
2429
id-token: write
25-
needs: release-please
26-
if: ${{ needs.release-please.outputs.release_created }}
2730

2831
steps:
2932
- name: Checkout repository

.github/workflows/size-limit.yml

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,13 +3,21 @@ on:
33
pull_request:
44
branches:
55
- master
6+
7+
permissions:
8+
pull-requests: write
9+
610
jobs:
711
size:
812
runs-on: ubuntu-latest
913
env:
1014
CI_JOB_NUMBER: 1
15+
1116
steps:
12-
- uses: actions/checkout@v5
13-
- uses: andresz1/size-limit-action@v1
17+
- name: Checkout repository
18+
uses: actions/checkout@v5
19+
20+
- name: Size Limit
21+
uses: andresz1/size-limit-action@v1
1422
with:
1523
github_token: ${{ secrets.GITHUB_TOKEN }}

.github/workflows/test.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: test
22
on: [push, pull_request]
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
test:
69
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)