ci: fix workflow permissions

Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
This commit is contained in:
CrazyMax 2024-10-29 09:48:47 +01:00
parent 181348397c
commit 6b2dc8ce56
No known key found for this signature in database
GPG Key ID: ADE44D8C9D44FBE4
4 changed files with 9 additions and 8 deletions

View File

@ -229,8 +229,6 @@ jobs:
permissions: permissions:
# required to write sarif report # required to write sarif report
security-events: write security-events: write
# required to check out the repository
contents: read
steps: steps:
- -
name: Checkout name: Checkout
@ -404,6 +402,9 @@ jobs:
release: release:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
permissions:
# required to create GitHub release
contents: write
needs: needs:
- test-integration - test-integration
- test-unit - test-unit

View File

@ -21,12 +21,10 @@ env:
jobs: jobs:
codeql: codeql:
runs-on: ubuntu-24.04
permissions: permissions:
actions: read actions: read
contents: read
security-events: write security-events: write
runs-on: ubuntu-24.04
steps: steps:
- -
name: Checkout name: Checkout

View File

@ -23,6 +23,9 @@ jobs:
open-pr: open-pr:
runs-on: ubuntu-24.04 runs-on: ubuntu-24.04
if: ${{ (github.event.release.prerelease != true || github.event.inputs.tag != '') && github.repository == 'docker/buildx' }} if: ${{ (github.event.release.prerelease != true || github.event.inputs.tag != '') && github.repository == 'docker/buildx' }}
permissions:
contents: write
pull-requests: write
steps: steps:
- -
name: Checkout docs repo name: Checkout docs repo

View File

@ -18,10 +18,9 @@ on:
jobs: jobs:
labeler: labeler:
permissions:
contents: read
pull-requests: write
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions:
pull-requests: write
steps: steps:
- -
name: Run name: Run