Merge pull request #99 from Sea-Haven-Industries/ci/harden-reusable-ci-permissions

ci: scope the three reusable CI workflows to contents:read
This commit is contained in:
Adam Moussa 2026-07-28 12:23:08 -04:00 • committed by GitHub
commit 3bdf11cd69
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
5 changed files with 17 additions and 0 deletions

View file

@ -20,6 +20,9 @@ on:
type: boolean type: boolean
default: true default: true
permissions:
contents: read
jobs: jobs:
ci: ci:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View file

@ -44,6 +44,9 @@ on:
type: boolean type: boolean
default: true default: true
permissions:
contents: read
jobs: jobs:
ci: ci:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View file

@ -56,6 +56,9 @@ on:
type: string type: string
default: "template.yaml" default: "template.yaml"
permissions:
contents: read
jobs: jobs:
ci: ci:
runs-on: ubuntu-latest runs-on: ubuntu-latest

View file

@ -6,5 +6,9 @@ on:
jobs: jobs:
deploy: deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
# reusable workflow's default — passed explicitly to pin against drift.
node-version: "24"
secrets: secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }} deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}

View file

@ -6,3 +6,7 @@ on:
jobs: jobs:
ci: ci:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Matches local dev (Node 24 / npm 11, lockfileVersion 3). This is also the
# reusable workflow's default — passed explicitly to pin against drift.
node-version: "24"