Merge pull request #10368 from nextcloud/defaultPermission

Setting token permissions to read-only follows the principle of least privilege.
This commit is contained in:
Álvaro Brey 2022-06-23 12:23:56 +02:00 committed by GitHub
commit 573b976e63
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
13 changed files with 50 additions and 13 deletions

View file

@ -6,6 +6,10 @@ on:
push:
branches: [ master, stable-* ]
permissions:
pull-requests: write
contents: write
jobs:
analysis:
runs-on: ubuntu-latest

View file

@ -4,6 +4,9 @@ on:
pull_request:
branches: [ master, stable-* ]
# Declare default permissions as read only.
permissions: read-all
jobs:
flavor:
runs-on: ubuntu-latest

View file

@ -3,6 +3,9 @@ on:
pull_request_target:
branches: [ master, stable-* ]
permissions:
pull-requests: write
jobs:
auto-approve:
runs-on: ubuntu-latest

View file

@ -4,6 +4,9 @@ on:
pull_request:
branches: [ master, stable-* ]
# Declare default permissions as read only.
permissions: read-all
jobs:
check:
runs-on: ubuntu-latest

View file

@ -4,6 +4,9 @@ on:
pull_request:
branches: [ master, stable-* ]
# Declare default permissions as read only.
permissions: read-all
jobs:
detectNewJavaFiles:
runs-on: ubuntu-latest

View file

@ -4,6 +4,9 @@ on:
pull_request:
branches: [ master, stable-* ]
# Declare default permissions as read only.
permissions: read-all
jobs:
detectSnapshot:
runs-on: ubuntu-latest

View file

@ -4,6 +4,9 @@ on:
pull_request:
branches: [ master, stable-* ]
# Declare default permissions as read only.
permissions: read-all
jobs:
validation:
name: "Validation"

View file

@ -4,6 +4,10 @@ on:
pull_request:
branches: [ master, stable-* ]
permissions:
pull-requests: write
contents: read
jobs:
qa:
runs-on: ubuntu-latest

View file

@ -4,6 +4,10 @@ on:
pull_request:
branches: [ master, stable-* ]
permissions:
contents: read
pull-requests: write
jobs:
screenshot:
runs-on: macOS-latest

View file

@ -3,6 +3,9 @@ on:
schedule:
- cron: '* */2 * * *'
permissions:
pull-requests: write
jobs:
stale:
runs-on: ubuntu-latest

View file

@ -6,6 +6,10 @@ on:
push:
branches: [ master, stable-* ]
permissions:
contents: read
pull-requests: write
jobs:
test:
runs-on: ubuntu-latest