Skip to content

Commit 979b69b

Browse files
committed
CI: Testing oidc
1 parent b4f3225 commit 979b69b

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

.github/workflows/release.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,13 +16,14 @@ on:
1616

1717
# Releases need permissions to read and write the repository contents.
1818
# GitHub considers creating releases and uploading assets as writing contents.
19-
permissions:
20-
contents: write
19+
permissions: {}
2120

2221
jobs:
2322

2423
unit_test:
2524
runs-on: ubuntu-latest
25+
permissions:
26+
contents: read
2627
steps:
2728
- name: Checkout code
2829
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
@@ -48,6 +49,8 @@ jobs:
4849
# Sonar scan is not required for dependabot PRs
4950
runs-on: ubuntu-latest
5051
needs: unit_test
52+
permissions:
53+
contents: read
5154
steps:
5255
- name: Checkout code
5356
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
@@ -96,6 +99,9 @@ jobs:
9699
goreleaser:
97100
runs-on: ubuntu-latest
98101
needs: [unit_test, sonarqube]
102+
permissions:
103+
contents: write
104+
id-token: write
99105
steps:
100106
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
101107
with:

0 commit comments

Comments
 (0)