Commit 918f911
authored
Add explicit permissions blocks to caller workflow files (#176)
## Summary
Adds explicit `permissions:` blocks to the workflow files that call
ITensorActions reusable workflows.
Most of these files previously declared no `permissions:` block and
inherited their `GITHUB_TOKEN` ceiling from the repository /
organization Actions defaults. After this change, each workflow's
permissions live in the YAML rather than in a settings page, and any
future change to the org or per-repo Actions default can only narrow
(never widen) what these workflows can do.
Each block declares the minimum the workflow actually needs (`contents:
read` for checkout-only workflows; elevated for Documentation gh-pages
deploy, TagBot tag creation, IntegrationTest's gate job, and
VersionCheck's PR-file lookup).
Verified by temporarily flipping this repo's per-repo Actions setting to
`default_workflow_permissions: read` and
`can_approve_pull_request_reviews: false` — the planned org-default end
state. All workflows pass.1 parent 3c6df30 commit 918f911
7 files changed
Lines changed: 17 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
| 5 | + | |
4 | 6 | | |
5 | 7 | | |
6 | 8 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
| 14 | + | |
13 | 15 | | |
14 | 16 | | |
15 | 17 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
9 | 11 | | |
10 | 12 | | |
11 | 13 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
14 | 17 | | |
15 | 18 | | |
16 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
9 | 12 | | |
10 | 13 | | |
11 | 14 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
| 23 | + | |
22 | 24 | | |
23 | 25 | | |
24 | 26 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
4 | 7 | | |
5 | 8 | | |
6 | 9 | | |
| |||
0 commit comments