Skip to content

Commit 1c97789

Browse files
committed
fix permissions
1 parent c328189 commit 1c97789

2 files changed

Lines changed: 7 additions & 4 deletions

File tree

.github/workflows/pull_request.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
secrets:
1515
AUTOMERGE_APP_ID: ${{ secrets.AUTOMERGE_APP_ID }}
1616
AUTOMERGE_PEM: ${{ secrets.AUTOMERGE_PEM }}
17-
17+
1818
pr_title_format_check:
1919
uses: ./.github/workflows/pr_title_check.yml
2020

@@ -30,14 +30,14 @@ jobs:
3030
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
3131
secrets:
3232
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
33-
33+
3434
tag_release:
3535
needs: get_config_values
3636
uses: ./.github/workflows/tag-release-devcontainer.yml
3737
permissions:
38-
contents: read
3938
packages: read
40-
attestations: read
39+
id-token: write
40+
contents: write
4141
with:
4242
dry_run: true
4343
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}

.github/workflows/release.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,9 @@ jobs:
2020
tag_release:
2121
needs: [quality_checks, get_config_values]
2222
uses: ./.github/workflows/tag-release-devcontainer.yml
23+
permissions:
24+
id-token: write
25+
contents: write
2326
with:
2427
dry_run: false
2528
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}

0 commit comments

Comments
 (0)