mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 09:23:11 +00:00
Merge pull request #99 from Sea-Haven-Industries/ci/harden-reusable-ci-permissions
ci: scope the three reusable CI workflows to contents:read
This commit is contained in:
commit
3bdf11cd69
5 changed files with 17 additions and 0 deletions
3
.github/workflows/ci-dotnet.yaml
vendored
3
.github/workflows/ci-dotnet.yaml
vendored
|
|
@ -20,6 +20,9 @@ on:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: true
|
default: true
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ci:
|
ci:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
|
||||||
3
.github/workflows/ci-python-sam.yaml
vendored
3
.github/workflows/ci-python-sam.yaml
vendored
|
|
@ -44,6 +44,9 @@ on:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: true
|
default: true
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ci:
|
ci:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
|
||||||
3
.github/workflows/ci-typescript-cdk.yaml
vendored
3
.github/workflows/ci-typescript-cdk.yaml
vendored
|
|
@ -56,6 +56,9 @@ on:
|
||||||
type: string
|
type: string
|
||||||
default: "template.yaml"
|
default: "template.yaml"
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
ci:
|
ci:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
|
|
||||||
|
|
@ -6,5 +6,9 @@ on:
|
||||||
jobs:
|
jobs:
|
||||||
deploy:
|
deploy:
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
|
||||||
|
with:
|
||||||
|
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
|
||||||
|
# reusable workflow's default — passed explicitly to pin against drift.
|
||||||
|
node-version: "24"
|
||||||
secrets:
|
secrets:
|
||||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||||
|
|
|
||||||
|
|
@ -6,3 +6,7 @@ on:
|
||||||
jobs:
|
jobs:
|
||||||
ci:
|
ci:
|
||||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
|
||||||
|
with:
|
||||||
|
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
|
||||||
|
# reusable workflow's default — passed explicitly to pin against drift.
|
||||||
|
node-version: "24"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue