CI: update permissions on workflows which get external secrets (#104792)

update permissions
This commit is contained in:
Kevin Minehart
2025-04-30 17:32:44 +00:00
committed by GitHub
parent 36b810e1cc
commit e36d774d0c
3 changed files with 6 additions and 8 deletions
+2 -3
View File
@@ -46,9 +46,7 @@ on:
default: false
type: boolean
permissions:
contents: read
id-token: write
permissions: {}
jobs:
main:
@@ -60,6 +58,7 @@ jobs:
DRY_RUN: ${{ inputs.dry_run }}
runs-on: ubuntu-latest
permissions:
id-token: write
contents: write
pull-requests: write
steps:
+2 -3
View File
@@ -13,15 +13,14 @@ on:
- "v*.*.*"
- "release-*"
permissions:
contents: read
id-token: write
permissions: {}
# Since this is run on a pull request, we want to apply the patches intended for the
# target branch onto the source branch, to verify compatibility before merging.
jobs:
dispatch-job:
permissions:
id-token: write
contents: read
actions: write
env:
+2 -2
View File
@@ -10,14 +10,14 @@ on:
- "v*.*.*"
- "release-*"
permissions:
id-token: write
permissions: {}
# This is run after the pull request has been merged, so we'll run against the target branch
jobs:
dispatch-job:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
actions: write
env: