Skip to content

Commit 3a8622c

Browse files
authored
bug(ci): set id-token permissions (#223)
1 parent 34890ca commit 3a8622c

File tree

4 files changed

+8
-2
lines changed

4 files changed

+8
-2
lines changed

.github/workflows/gemini-dispatch.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,8 +108,9 @@ jobs:
108108
uses: './.github/workflows/gemini-review.yml'
109109
permissions:
110110
contents: 'read'
111-
pull-requests: 'write'
111+
id-token: 'write'
112112
issues: 'write'
113+
pull-requests: 'write'
113114
with:
114115
additional_context: '${{ needs.dispatch.outputs.additional_context }}'
115116
secrets: 'inherit'
@@ -121,6 +122,7 @@ jobs:
121122
uses: './.github/workflows/gemini-triage.yml'
122123
permissions:
123124
contents: 'read'
125+
id-token: 'write'
124126
issues: 'write'
125127
pull-requests: 'write'
126128
with:
@@ -134,6 +136,7 @@ jobs:
134136
uses: './.github/workflows/gemini-invoke.yml'
135137
permissions:
136138
contents: 'read'
139+
id-token: 'write'
137140
issues: 'write'
138141
pull-requests: 'write'
139142
with:

.github/workflows/gemini-invoke.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ jobs:
2121
runs-on: 'ubuntu-latest'
2222
permissions:
2323
contents: 'read'
24+
id-token: 'write'
2425
issues: 'write'
2526
pull-requests: 'write'
2627
steps:

.github/workflows/gemini-review.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,8 +22,9 @@ jobs:
2222
timeout-minutes: 7
2323
permissions:
2424
contents: 'read'
25-
pull-requests: 'write'
25+
id-token: 'write'
2626
issues: 'write'
27+
pull-requests: 'write'
2728
steps:
2829
- name: 'Mint identity token'
2930
id: 'mint_identity_token'

.github/workflows/gemini-triage.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,7 @@ jobs:
2525
selected_labels: '${{ env.SELECTED_LABELS }}'
2626
permissions:
2727
contents: 'read'
28+
id-token: 'write'
2829
issues: 'read'
2930
pull-requests: 'read'
3031
steps:

0 commit comments

Comments
 (0)