Skip to content

Commit 4718b0d

Browse files
authored
ci: scope down GitHub Token permissions (#3217)
1 parent 1a7301b commit 4718b0d

File tree

6 files changed

+25
-0
lines changed

6 files changed

+25
-0
lines changed

.github/workflows/closed-issue-message.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,10 @@ name: Closed Issue Message
22
on:
33
issues:
44
types: [closed]
5+
6+
permissions:
7+
issues: write
8+
59
jobs:
610
auto_comment:
711
runs-on: ubuntu-latest

.github/workflows/codegen.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,10 @@ on:
66
pull_request:
77
branches: [ main ]
88

9+
10+
permissions:
11+
contents: read
12+
913
env:
1014
# get owner of the repository. used by forks.
1115
SMITHY_GO_REPOSITORY: ${{ github.event.pull_request.head.repo.owner.login }}/smithy-go

.github/workflows/go.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ on:
99
- main
1010
- 'feat-**'
1111

12+
13+
permissions:
14+
contents: read
15+
1216
env:
1317
EACHMODULE_CONCURRENCY: 2
1418
SMITHY_GO_REPOSITORY: ${{ github.event.pull_request.head.repo.owner.login }}/smithy-go

.github/workflows/license-check.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,10 @@ name: License Scan
22

33
on: [pull_request]
44

5+
6+
permissions:
7+
contents: read
8+
59
jobs:
610
licensescan:
711
name: License Scan

.github/workflows/snapshot.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ on:
99
- main
1010
- 'feat-**'
1111

12+
13+
permissions:
14+
contents: read
15+
1216
env:
1317
EACHMODULE_CONCURRENCY: 2
1418
SMITHY_GO_REPOSITORY: ${{ github.event.pull_request.head.repo.owner.login }}/smithy-go

.github/workflows/stale_issue.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,11 @@ on:
55
schedule:
66
- cron: "0 0 * * *"
77

8+
9+
permissions:
10+
issues: write
11+
pull-requests: write
12+
813
jobs:
914
cleanup:
1015
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)