Skip to content

Commit 520c903

Browse files
authored
Merge pull request #2267 from stackhpc/ci-permission-update
Update Pull Request workflow job permissions
2 parents 4e95c88 + a1bcc64 commit 520c903

1 file changed

Lines changed: 11 additions & 0 deletions

File tree

.github/workflows/stackhpc-pull-request.yml

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ jobs:
1616
runs-on: ubuntu-24.04
1717
permissions:
1818
pull-requests: read
19+
packages: none
1920
name: Check changed files
2021
if: github.repository == 'stackhpc/stackhpc-kayobe-config'
2122
needs:
@@ -113,6 +114,9 @@ jobs:
113114

114115
build-kayobe-image:
115116
name: Build Kayobe Image
117+
permissions:
118+
contents: read
119+
packages: write # required by docker/build-push-action
116120
needs:
117121
- check-changes
118122
uses: ./.github/workflows/stackhpc-build-kayobe-image.yml
@@ -122,6 +126,7 @@ jobs:
122126

123127
check-tags:
124128
name: Check container image tags
129+
permissions: {}
125130
needs:
126131
- check-changes
127132
- build-kayobe-image
@@ -134,6 +139,7 @@ jobs:
134139

135140
all-in-one-ubuntu-noble-ovn:
136141
name: aio (Ubuntu Noble OVN)
142+
permissions: {}
137143
needs:
138144
- check-changes
139145
- build-kayobe-image
@@ -151,6 +157,7 @@ jobs:
151157

152158
all-in-one-rocky-9-ovs:
153159
name: aio (Rocky 9 OVS)
160+
permissions: {}
154161
needs:
155162
- check-changes
156163
- build-kayobe-image
@@ -168,6 +175,7 @@ jobs:
168175

169176
all-in-one-rocky-9-ovn:
170177
name: aio (Rocky 9 OVN)
178+
permissions: {}
171179
needs:
172180
- check-changes
173181
- build-kayobe-image
@@ -187,6 +195,7 @@ jobs:
187195

188196
all-in-one-upgrade-ubuntu-jammy-to-noble-ovn:
189197
name: aio upgrade (Ubuntu Jammy to Noble OVN)
198+
permissions: {}
190199
needs:
191200
- check-changes
192201
- build-kayobe-image
@@ -205,6 +214,7 @@ jobs:
205214

206215
all-in-one-upgrade-rocky-9-ovn:
207216
name: aio upgrade (Rocky 9 OVN)
217+
permissions: {}
208218
needs:
209219
- check-changes
210220
- build-kayobe-image
@@ -223,6 +233,7 @@ jobs:
223233

224234
all-in-one-upgrade-rocky-9-ovs:
225235
name: aio upgrade (Rocky 9 OVS)
236+
permissions: {}
226237
needs:
227238
- check-changes
228239
- build-kayobe-image

0 commit comments

Comments
 (0)