Skip to content

Commit d16bc44

Browse files
committed
move permissions to job level
1 parent 1c77d9a commit d16bc44

2 files changed

Lines changed: 12 additions & 7 deletions

File tree

.github/workflows/build-and-tag.yaml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,13 +24,14 @@ on:
2424
branches:
2525
- 'ozone-**'
2626

27-
permissions:
28-
contents: read
29-
packages: write
27+
permissions: { }
3028

3129
jobs:
3230
build:
3331
uses: ./.github/workflows/build.yaml
32+
permissions:
33+
contents: read
34+
packages: write
3435

3536
tag:
3637
needs: build
@@ -39,6 +40,9 @@ jobs:
3940
DOCKERHUB_USER: ${{ secrets.DOCKERHUB_USER }}
4041
IMAGE_ID: ${{ needs.build.outputs.image-id }}
4142
REGISTRIES: ghcr.io # docker.io is appended dynamically
43+
permissions:
44+
contents: read
45+
packages: write
4246
steps:
4347
- name: Generate tags
4448
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6.0.0

.github/workflows/build.yaml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,16 +35,17 @@ concurrency:
3535
group: ${{ github.sha }}
3636
cancel-in-progress: false
3737

38-
permissions:
39-
contents: read
40-
packages: write
41-
4238
env:
4339
OZONE_RUNNER_IMAGE: ghcr.io/apache/ozone-runner
4440

41+
permissions: { }
42+
4543
jobs:
4644
build:
4745
runs-on: ubuntu-latest
46+
permissions:
47+
contents: read
48+
packages: write
4849
outputs:
4950
image-id: ${{ steps.meta.outputs.tags }}
5051
steps:

0 commit comments

Comments
 (0)