.github/.github/workflows/ci-dotnet.yaml
Adam Moussa 1562cbda8e
ci: scope the three reusable CI workflows to contents:read
ci-python-sam, ci-typescript-cdk and ci-dotnet declared no permissions
at any level, unlike every other workflow here. A reusable workflow that
declares nothing inherits the CALLER's token scopes, and these are
called from deploy repos, so a lint/test/synth job could run holding an
OIDC-mintable token it has no use for. None of the three references
GITHUB_TOKEN, github.token, gh, or any secret, so contents:read is all
they need to check out and build.

Also pass node-version explicitly in the cdk-deploy and ci-node
templates. cicd.md requires callers to pin it so lockfileVersion 3 from
local Node 24 / npm 11 cannot drift from the runner, but no template
did. Only these two targets accept the input; sam-deploy, dotnet-eb,
dependency-review and labeler do not, so they are left alone.

Verified against all 22 callers across the org that none grants
permissions omitting contents:read, so no repo's CI breaks on the
caller-cannot-be-exceeded rule.
2026-07-28 12:13:07 -04:00

51 lines
1.3 KiB
YAML

name: CI — .NET
on:
workflow_call:
inputs:
dotnet-version:
description: ".NET SDK version"
type: string
default: "8.0.x"
working-directory:
description: "Directory containing the solution/project"
type: string
default: "."
solution:
description: "Solution or project file to build"
type: string
default: "*.sln"
run-tests:
description: "Run dotnet test"
type: boolean
default: true
permissions:
contents: read
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 20
concurrency:
group: ci-dotnet-${{ github.workflow }}-${{ github.ref }}-${{ inputs.working-directory }}
cancel-in-progress: true
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- uses: actions/checkout@v7
- uses: actions/setup-dotnet@v6
with:
dotnet-version: ${{ inputs.dotnet-version }}
- name: Restore
run: dotnet restore ${{ inputs.solution }}
- name: Build
run: dotnet build ${{ inputs.solution }} --no-restore --configuration Release
- name: Test
if: ${{ inputs.run-tests }}
run: dotnet test ${{ inputs.solution }} --no-build --configuration Release