Skip to content

Commit 6b59415

Browse files
ci(github): set permissions in workflows
1 parent e54983a commit 6b59415

File tree

4 files changed

+17
-3
lines changed

4 files changed

+17
-3
lines changed

.github/workflows/assign-reviewer.yml

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,22 @@
11
name: Assign Reviewer
22
on: pull_request_target
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
assign-reviewer:
69
runs-on: ubuntu-latest
710
steps:
811
- name: Assign reviewer
912
if: >
10-
startsWith(github.event.pull_request.title, 'build(deps-dev): bump ') == false &&
11-
contains(github.event.action, 'opened')
13+
github.actor != 'dependabot[bot]'
14+
&& startsWith(github.event.pull_request.title, 'build(deps-dev): bump ') == false
15+
&& contains(github.event.action, 'opened')
1216
run: >
1317
gh pr edit ${{ github.event.pull_request.html_url }}
1418
--add-assignee ${{ github.event.pull_request.user.login }}
1519
--add-reviewer remarkablemark
1620
env:
17-
GITHUB_TOKEN: ${{ github.token }}
21+
GH_TOKEN: ${{ github.token }}
1822
continue-on-error: true

.github/workflows/build.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: build
22
on: [push, pull_request]
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
build:
69
runs-on: ubuntu-latest

.github/workflows/commitlint.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
name: commitlint
22
on: [push, pull_request]
33

4+
permissions:
5+
contents: read
6+
47
jobs:
58
commitlint:
69
runs-on: ubuntu-latest

.github/workflows/size-limit.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,10 @@ on:
33
pull_request:
44
branches:
55
- master
6+
7+
permissions:
8+
pull-requests: write
9+
610
jobs:
711
size:
812
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)