Skip to content

Commit 5d67234

Browse files
authored
Merge pull request #15 from openai/tighten-automerge-permissions
Tighten automerge workflow permissions
2 parents 853b001 + 83b1e4f commit 5d67234

1 file changed

Lines changed: 8 additions & 5 deletions

File tree

.github/workflows/auto-merge-goreleaser.yml

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,7 @@ on:
77
types:
88
- completed
99

10-
permissions:
11-
actions: read
12-
checks: read
13-
contents: write
14-
pull-requests: write
10+
permissions: {}
1511

1612
concurrency:
1713
group: goreleaser-automerge-${{ github.event.workflow_run.head_branch }}
@@ -24,6 +20,11 @@ jobs:
2420
github.event.workflow_run.conclusion == 'success' &&
2521
github.event.workflow_run.event == 'pull_request'
2622
runs-on: ubuntu-latest
23+
permissions:
24+
actions: read
25+
checks: read
26+
contents: read
27+
pull-requests: read
2728
outputs:
2829
pr-number: ${{ steps.verify.outputs.pr-number }}
2930

@@ -86,6 +87,8 @@ jobs:
8687
needs: verify
8788
runs-on: ubuntu-latest
8889
environment: goreleaser-automerge
90+
permissions:
91+
contents: read
8992

9093
steps:
9194
- name: Create GoReleaser app token

0 commit comments

Comments
 (0)