Skip to content

Commit 43a8a7a

Browse files
authored
Set explicit permissions for GitHub Actions workflows (#1048)
1 parent 2ceee6d commit 43a8a7a

File tree

2 files changed

+9
-0
lines changed

2 files changed

+9
-0
lines changed

.github/workflows/per-pr.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ on: # rebuild any PRs and main branch changes
66
branches:
77
- master
88

9+
permissions:
10+
contents: read
11+
actions: write
12+
913
concurrency:
1014
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
1115
cancel-in-progress: true

crates/common/protos/api_upstream/.github/workflows/create-release.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,9 @@ on:
2020
description: An ID used by external tools to identify workflow runs(can be left empty when running manually)
2121
default: "none"
2222
type: string
23+
24+
permissions:
25+
contents: read
2326
jobs:
2427
dispatch:
2528
runs-on: ubuntu-latest
@@ -130,6 +133,8 @@ jobs:
130133
gh release create "$TAG" --target "$REF" --latest --generate-notes --notes-start-tag "$BASE_TAG" --draft
131134
132135
release-api-go:
136+
permissions:
137+
contents: write
133138
needs: [prepare-inputs, create-release]
134139
if: |
135140
!cancelled() &&

0 commit comments

Comments
 (0)