Skip to content

Commit dd6b834

Browse files
authored
Merge pull request #3442 from NationalSecurityAgency/t#3441/ci_perm
#3441: set jobs' permissions to read
2 parents 9ff3edc + b79885c commit dd6b834

6 files changed

+26
-6
lines changed

.github/workflows/build-and-test-email-confirmation.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,8 @@ on:
2222
jobs:
2323
ci:
2424
runs-on: ubuntu-latest
25-
25+
permissions:
26+
contents: read
2627
services:
2728
postgres:
2829
# Docker Hub image

.github/workflows/build-and-test-oauth.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@ on:
2626
jobs:
2727
build-skills-service-for-ui-tests:
2828
runs-on: ubuntu-latest
29-
29+
permissions:
30+
contents: read
3031
steps:
3132
- uses: actions/checkout@v4
3233

@@ -65,6 +66,8 @@ jobs:
6566

6667
ui-oauth-tests:
6768
runs-on: ubuntu-latest
69+
permissions:
70+
contents: read
6871
needs: [build-skills-service-for-ui-tests]
6972
strategy:
7073
# when one test fails, DO NOT cancel the other

.github/workflows/build-and-test-rabbitmq.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@ on:
2626
jobs:
2727
build-skills-service-for-ui-tests:
2828
runs-on: ubuntu-latest
29-
29+
permissions:
30+
contents: read
3031
steps:
3132
- uses: actions/checkout@v4
3233

@@ -65,6 +66,8 @@ jobs:
6566

6667
ui-stomp-tests:
6768
runs-on: ubuntu-latest
69+
permissions:
70+
contents: read
6871
needs: [build-skills-service-for-ui-tests]
6972
strategy:
7073
# when one test fails, DO NOT cancel the other

.github/workflows/build-and-test-ssl.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,8 @@ jobs:
3030

3131
service-against-postgresql:
3232
runs-on: ubuntu-latest
33-
33+
permissions:
34+
contents: read
3435
strategy:
3536
# when one test fails, DO NOT cancel the other containers
3637
fail-fast: false

.github/workflows/build-and-test.yml

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,8 @@ on:
3232
jobs:
3333
build-skills-service-for-ui-tests:
3434
runs-on: ubuntu-latest
35-
35+
permissions:
36+
contents: read
3637
steps:
3738
- uses: actions/checkout@v4
3839

@@ -76,6 +77,8 @@ jobs:
7677
ui-tests-against-postgres:
7778
# if: github.event_name == 'schedule-never'
7879
runs-on: ubuntu-latest
80+
permissions:
81+
contents: read
7982
needs: [build-skills-service-for-ui-tests]
8083
strategy:
8184
fail-fast: false
@@ -182,6 +185,8 @@ jobs:
182185
183186
combine-cypress-mochawesome-results:
184187
runs-on: ubuntu-latest
188+
permissions:
189+
contents: read
185190
if: ${{ !cancelled() }}
186191
# if: github.event_name == 'schedule-never'
187192
needs: [ui-tests-against-postgres]
@@ -224,6 +229,8 @@ jobs:
224229
ui-tests-against-postgres-cypress-dashboard:
225230
if: github.event_name == 'schedule-never'
226231
runs-on: ubuntu-latest
232+
permissions:
233+
contents: read
227234
# container:
228235
# image: cypress/browsers:node-22.16.0-chrome-137.0.7151.119-1-ff-139.0.4-edge-137.0.3296.62-1
229236
needs: [build-skills-service-for-ui-tests]
@@ -320,6 +327,8 @@ jobs:
320327
321328
service-against-postgresql:
322329
runs-on: ubuntu-latest
330+
permissions:
331+
contents: read
323332
strategy:
324333
# when one test fails, DO NOT cancel the other containers
325334
fail-fast: false
@@ -398,6 +407,8 @@ jobs:
398407
399408
combine-surefire-reports:
400409
runs-on: ubuntu-latest
410+
permissions:
411+
contents: read
401412
if: ${{ !cancelled() }}
402413
needs: [service-against-postgresql]
403414
steps:

.github/workflows/generate-images-for-regression-tests.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,8 @@ on:
2020
jobs:
2121
generate-images-for-regression-tests:
2222
runs-on: ubuntu-latest
23-
23+
permissions:
24+
contents: read
2425
services:
2526
postgres:
2627
# Docker Hub image

0 commit comments

Comments
 (0)