Adopt org conventions: reusable-workflow CI, dependabot, labels #10
2 changed files with 6 additions and 0 deletions
3
.github/workflows/ci.yaml
vendored
3
.github/workflows/ci.yaml
vendored
|
|
@ -4,6 +4,9 @@ on:
|
|||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
# Thin wrapper over the org reusable CI. The reusable runs ruff lint/format +
|
||||
|
|
|
|||
3
.github/workflows/dependency-review.yml
vendored
3
.github/workflows/dependency-review.yml
vendored
|
|
@ -3,6 +3,9 @@ name: Dependency Review
|
|||
on:
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
review:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
|
||||
|
Fixed: added permissions in Fixed: added permissions in 3d066e0
|
||||
|
|
|
|||
Reference in a new issue
CodeQL / Workflow does not contain permissions
Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}
Show more details