Skip to content

Commit 1cb710e

Browse files
authored
fix: adds permissions to all workflows (#505)
1 parent ae11040 commit 1cb710e

15 files changed

+109
-5
lines changed

.github/workflows/audit.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ on:
88
# "At 08:00 UTC (01:00 PT) on Monday" https://crontab.guru/#0_8_*_*_1
99
- cron: "0 8 * * 1"
1010

11+
permissions:
12+
contents: read
13+
1114
jobs:
1215
audit:
1316
name: Audit Dependencies

.github/workflows/ci-release.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,10 @@ on:
1818
required: true
1919
type: string
2020

21+
permissions:
22+
contents: read
23+
checks: write
24+
2125
jobs:
2226
lint-all:
2327
name: Lint All

.github/workflows/ci-test-workspace.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,9 @@ on:
1616
# "At 09:00 UTC (02:00 PT) on Monday" https://crontab.guru/#0_9_*_*_1
1717
- cron: "0 9 * * 1"
1818

19+
permissions:
20+
contents: read
21+
1922
jobs:
2023
lint:
2124
name: Lint

.github/workflows/ci.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,9 @@ on:
1616
# "At 09:00 UTC (02:00 PT) on Monday" https://crontab.guru/#0_9_*_*_1
1717
- cron: "0 9 * * 1"
1818

19+
permissions:
20+
contents: read
21+
1922
jobs:
2023
lint:
2124
name: Lint

.github/workflows/codeql-analysis.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,9 @@ on:
1313
# "At 10:00 UTC (03:00 PT) on Monday" https://crontab.guru/#0_10_*_*_1
1414
- cron: "0 10 * * 1"
1515

16+
permissions:
17+
contents: read
18+
1619
jobs:
1720
analyze:
1821
name: Analyze

.github/workflows/pull-request.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,9 @@ on:
1010
- edited
1111
- synchronize
1212

13+
permissions:
14+
contents: read
15+
1316
jobs:
1417
commitlint:
1518
name: Lint Commits

.github/workflows/release-integration.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,9 @@ on:
1919
PUBLISH_TOKEN:
2020
required: true
2121

22+
permissions:
23+
contents: read
24+
2225
jobs:
2326
publish:
2427
name: Publish

lib/content/audit-yml.hbs

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ on:
66
# "At 08:00 UTC (01:00 PT) on Monday" https://crontab.guru/#0_8_*_*_1
77
- cron: "0 8 * * 1"
88

9+
permissions:
10+
contents: read
11+
912
jobs:
1013
audit:
1114
{{> jobYml jobName="Audit Dependencies" jobDepFlags="--package-lock" }}

lib/content/ci-release-yml.hbs

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,10 @@ on:
1717
required: true
1818
type: string
1919

20+
permissions:
21+
contents: read
22+
checks: write
23+
2024
jobs:
2125
lint-all:
2226
{{> jobYml

lib/content/ci-yml.hbs

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,9 @@ name: CI {{~#if isWorkspace}} - {{ pkgName }}{{/if}}
33
on:
44
{{> onCiYml }}
55

6+
permissions:
7+
contents: read
8+
69
jobs:
710
lint:
811
{{> jobYml jobName="Lint" }}

0 commit comments

Comments
 (0)