Skip to content

Commit 92c7672

Browse files
[BRE-1333] [key-connector] Update workflow permissions (#243)
* removed permissions from job level * added permission to app token generation step * explicitly define empty permission set at workflow level
1 parent 5da3fe3 commit 92c7672

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

.github/workflows/version-bump.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,14 +12,14 @@ on:
1212
default: false
1313
type: boolean
1414

15+
permissions: {}
16+
1517
jobs:
1618
bump_version:
1719
name: Bump version
1820
runs-on: ubuntu-22.04
1921
permissions:
20-
contents: write
2122
id-token: write
22-
pull-requests: write
2323
outputs:
2424
version: ${{ steps.set-final-version-output.outputs.version }}
2525

@@ -53,6 +53,7 @@ jobs:
5353
with:
5454
app-id: ${{ steps.get-kv-secrets.outputs.BW-GHAPP-ID }}
5555
private-key: ${{ steps.get-kv-secrets.outputs.BW-GHAPP-KEY }}
56+
permission-contents: write
5657

5758
- name: Check out repo
5859
uses: actions/checkout@eef61447b9ff4aafe5dcd4e0bbf5d482be7e7871 # v4.2.1

0 commit comments

Comments
 (0)