Skip to content

Commit f6273f4

Browse files
committed
ci(build-and-deploy): fix security warning (add permissions to workflow)
also adds missing env vars for latest model deployments
1 parent 395264d commit f6273f4

File tree

1 file changed

+6
-2
lines changed

1 file changed

+6
-2
lines changed

.github/workflows/build-and-deploy.yml

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,9 @@ on:
1616
- "postcss.config.json"
1717
- "tsconfig.json"
1818

19+
permissions:
20+
contents: read
21+
1922
concurrency:
2023
group: ${{ github.workflow }}-${{ github.ref }}
2124
cancel-in-progress: true
@@ -26,12 +29,13 @@ env:
2629
AZURE_WEBAPP_PACKAGE_PATH: "."
2730
AZURE_WEBAPP_PUBLISH_PROFILE: ${{ secrets.AZURE_WEBAPP_PUBLISH_PROFILE }}
2831
AZURE_OPENAI_API_KEY: ${{ secrets.AZURE_OPENAI_API_KEY }}
32+
AZURE_OPENAI_API_VERSION: ${{ secrets.AZURE_OPENAI_API_VERSION }}
2933
AZURE_OPENAI_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_DEPLOYMENT_NAME }}
3034
AZURE_OPENAI_GPT4O_DEPLOYMENT: ${{ secrets.AZURE_OPENAI_GPT4O_DEPLOYMENT }}
3135
AZURE_OPENAI_GPT4O_MINI_DEPLOYMENT: ${{ secrets.AZURE_OPENAI_GPT4O_MINI_DEPLOYMENT }}
32-
AZURE_OPENAI_GPT45_DEPLOYMENT: ${{ secrets.AZURE_OPENAI_GPT45_DEPLOYMENT }}
3336
AZURE_OPENAI_GPT41_DEPLOYMENT: ${{ secrets.AZURE_OPENAI_GPT41_DEPLOYMENT }}
34-
AZURE_OPENAI_API_VERSION: ${{ secrets.AZURE_OPENAI_API_VERSION }}
37+
AZURE_OPENAI_GPT41_MINI_DEPLOYMENT: ${{ secrets.AZURE_OPENAI_GPT41_MINI_DEPLOYMENT }}
38+
AZURE_OPENAI_GPT41_NANO_DEPLOYMENT: ${{ secrets.AZURE_OPENAI_GPT41_NANO_DEPLOYMENT }}
3539
MS_TEAMS_WEBHOOK_URL: ${{ secrets.MS_TEAMS_WEBHOOK_URL }}
3640
APP_DISPLAY_NAME: "Cloud Team GPT4 Chat"
3741

0 commit comments

Comments
 (0)