CI: update permissions on workflows which get external secrets (#104792) (#105787)

update permissions

(cherry picked from commit e36d774d0c)

Co-authored-by: Kevin Minehart <5140827+kminehart@users.noreply.github.com>
This commit is contained in:
Kevin Yu
2025-05-21 13:55:50 -07:00
committed by GitHub
co-authored by Kevin Minehart
parent f8dafd73eb
commit 3578bab394
3 changed files with 4 additions and 2 deletions
+1
View File
@@ -63,6 +63,7 @@ jobs:
DRY_RUN: ${{ inputs.dry_run }} DRY_RUN: ${{ inputs.dry_run }}
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions: permissions:
id-token: write
contents: write contents: write
pull-requests: write pull-requests: write
steps: steps:
@@ -20,6 +20,7 @@ permissions: {}
jobs: jobs:
dispatch-job: dispatch-job:
permissions: permissions:
id-token: write
contents: read contents: read
actions: write actions: write
env: env:
+2 -2
View File
@@ -10,14 +10,14 @@ on:
- "v*.*.*" - "v*.*.*"
- "release-*" - "release-*"
permissions: permissions: {}
id-token: write
# This is run after the pull request has been merged, so we'll run against the target branch # This is run after the pull request has been merged, so we'll run against the target branch
jobs: jobs:
dispatch-job: dispatch-job:
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions: permissions:
id-token: write
contents: read contents: read
actions: write actions: write
env: env: