Skip to content

Commit

Permalink
Merge pull request #3927 from github/aeisenberg/add-permissions-actions
Browse files Browse the repository at this point in the history
Add permissions block and actions analysis
  • Loading branch information
aeisenberg authored Feb 14, 2025
2 parents 18dba23 + acc46ce commit 93645de
Show file tree
Hide file tree
Showing 6 changed files with 26 additions and 1 deletion.
6 changes: 6 additions & 0 deletions .github/workflows/cli-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,8 @@ jobs:
find-nightly:
name: Find Nightly Release
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
url: ${{ steps.get-url.outputs.nightly-url }}
steps:
Expand All @@ -33,6 +35,8 @@ jobs:
set-matrix:
name: Set Matrix for cli-test
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
Expand All @@ -47,6 +51,8 @@ jobs:
runs-on: ${{ matrix.os }}
needs: [find-nightly, set-matrix]
timeout-minutes: 30
permissions:
contents: read
strategy:
matrix:
os: [ubuntu-latest, windows-latest]
Expand Down
8 changes: 7 additions & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,12 @@ on:
jobs:
codeql:
runs-on: ubuntu-latest
strategy:
matrix:
language:
- javascript
- actions
fail-fast: false

permissions:
contents: read
Expand All @@ -24,7 +30,7 @@ jobs:
- name: Initialize CodeQL
uses: github/codeql-action/init@main
with:
languages: javascript
languages: ${{ matrix.language }}
config-file: ./.github/codeql/codeql-config.yml
tools: latest

Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/e2e-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,9 @@ on:
pull_request:
branches: [main]

permissions:
contents: read

jobs:
e2e-test:
name: E2E Test
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/label-issue.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ on:
issues:
types: [opened]

permissions:
issues: write

jobs:
label:
name: Label issue
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ on:
branches:
- main

permissions:
contents: read

jobs:
build:
name: Build
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,8 @@ jobs:
build:
name: Release
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
Expand Down Expand Up @@ -156,6 +158,8 @@ jobs:
needs: build
environment: publish-open-vsx
runs-on: ubuntu-latest
permissions:
contents: read
env:
OPEN_VSX_TOKEN: ${{ secrets.OPEN_VSX_TOKEN }}
steps:
Expand Down

0 comments on commit 93645de

Please sign in to comment.