Skip to content

Commit a0bbc61

Browse files
committed
add dd-octo-sts policies
1 parent 5a89c40 commit a0bbc61

File tree

2 files changed

+29
-0
lines changed

2 files changed

+29
-0
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# Trust policy for pre-commit fixes on pull requests
2+
# Allows pushing pre-commit fixes back to PR branches
3+
# Will be called in reusable-pre-commit.yml
4+
issuer: https://token.actions.githubusercontent.com
5+
subject: repo:DataDog/datadog-api-client-java:pull_request
6+
7+
claim_pattern:
8+
event_name: pull_request
9+
# Even when running pull_request, the workflow code comes from the base branch, hence refs/heads/master
10+
job_workflow_ref: DataDog/datadog-api-client-java/\.github/workflows/reusable-pre-commit\.yml@refs/heads/master
11+
repository: DataDog/datadog-api-client-java
12+
ref: refs/heads/master
13+
14+
permissions:
15+
contents: write # Required for pushing pre-commit fixes
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Trust policy for creating releases on master branch
2+
# Restricted to master branch (protected ref) for security
3+
# Will be called in release.yml
4+
issuer: https://token.actions.githubusercontent.com
5+
subject: repo:DataDog/datadog-api-client-java:pull_request
6+
7+
claim_pattern:
8+
event_name: pull_request
9+
job_workflow_ref: DataDog/datadog-api-client-java/\.github/workflows/release\.yml@refs/heads/master
10+
repository: DataDog/datadog-api-client-java
11+
ref: refs/heads/master
12+
13+
permissions:
14+
contents: write

0 commit comments

Comments
 (0)