chore(workflows): set workflow permissions in jobs

This commit is contained in:
2024-08-21 11:03:25 +03:00
parent 92b8749e34
commit c18ea6bebe
12 changed files with 54 additions and 54 deletions

View File

@@ -8,14 +8,14 @@ on:
- "composer.json"
- "composer.lock"
permissions:
contents: write
statuses: write
jobs:
ComposerInstall:
runs-on: ubuntu-latest
permissions:
contents: write
statuses: write
strategy:
matrix:
operating-system: ["ubuntu-latest"]

View File

@@ -8,15 +8,17 @@ on:
schedule:
- cron: "00 23 * * 0"
permissions:
contents: write
statuses: write
pull-requests: write
jobs:
CompressOnDemandOrSchedule:
name: calibreapp/image-actions
runs-on: ubuntu-latest
permissions:
contents: write
statuses: write
pull-requests: write
steps:
- name: Checkout Repo
uses: actions/checkout@v4

View File

@@ -12,12 +12,11 @@ name: "Dependency Review"
on: [pull_request]
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: "Checkout Repository"
uses: actions/checkout@v4

View File

@@ -7,18 +7,18 @@ on:
pull_request:
branches: [main]
permissions:
contents: write
statuses: write
jobs:
laravel-tests:
runs-on: ubuntu-latest
permissions:
contents: write
statuses: write
steps:
- uses: shivammathur/setup-php@v2
with:
php-version: "8.1"
php-version: "8.3"
- uses: actions/checkout@v4

View File

@@ -11,17 +11,18 @@ on:
- "**.png"
- "**.webp"
permissions:
contents: write
statuses: write
pull-requests: write
jobs:
CompressInPR:
# Only run on Pull Requests within the same repository, and not from forks.
if: github.event.pull_request.head.repo.full_name == github.repository
name: calibreapp/image-actions
runs-on: ubuntu-latest
permissions:
contents: write
statuses: write
pull-requests: write
steps:
- name: Checkout Repo
uses: actions/checkout@v4

View File

@@ -24,14 +24,6 @@ on:
pull_request:
branches: [master, main]
############################################
# Grant status permission for MULTI_STATUS #
############################################
permissions:
contents: read
packages: read
statuses: write
###############
# Set the Job #
###############
@@ -42,6 +34,14 @@ jobs:
# Set the agent to run on
runs-on: ubuntu-latest
############################################
# Grant status permission for MULTI_STATUS #
############################################
permissions:
contents: read
packages: read
statuses: write
##################
# Load all steps #
##################

View File

@@ -4,14 +4,13 @@ name: Release Drafter
on:
workflow_call:
permissions:
contents: write
statuses: write
jobs:
update_release_draft:
name: ✏️ Draft release
runs-on: ubuntu-latest
permissions:
contents: write
statuses: write
steps:
- name: 🚀 Run Release Drafter
uses: release-drafter/release-drafter@v6.0.0

View File

@@ -7,13 +7,12 @@ on:
schedule:
- cron: "0 0 1 * *" # 1st of every month at midnight
permissions:
contents: write
jobs:
release:
name: Release
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4

View File

@@ -3,15 +3,16 @@ name: Reviewdog Linters
on: [push]
permissions:
contents: read
packages: read
statuses: write
jobs:
linters:
name: Linters
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
statuses: write
steps:
- uses: actions/checkout@v4

View File

@@ -7,15 +7,16 @@ on:
workflow_call:
workflow_dispatch:
permissions:
contents: write # only for delete-branch option
issues: write
pull-requests: write
jobs:
stale:
name: 🧹 Clean up stale issues and PRs
runs-on: ubuntu-latest
permissions:
contents: write # only for delete-branch option
issues: write
pull-requests: write
steps:
- name: 🚀 Run stale
uses: actions/stale@v9.0.0

View File

@@ -12,13 +12,12 @@ on:
schedule:
- cron: "0 0 * * *" # Every day at midnight
permissions:
contents: write
statuses: write
jobs:
sync-labels:
runs-on: ubuntu-latest
permissions:
contents: write
statuses: write
outputs:
repos: ${{ steps.repos.outputs.REPOS }}
steps:

View File

@@ -13,13 +13,12 @@ on:
workflow_call:
workflow_dispatch:
permissions:
issues: write
jobs:
labels:
name: ♻️ Sync labels
runs-on: ubuntu-latest
permissions:
issues: write
steps:
- name: ⤵️ Download latest labels definitions
run: |