Skip to content

Commit 09306c4

Browse files
committed
set permissions for the entire workflow
1 parent fc99916 commit 09306c4

File tree

1 file changed

+4
-9
lines changed

1 file changed

+4
-9
lines changed

.github/workflows/release.yml

+4-9
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ on:
55
tags:
66
- "[0-9]+.[0-9]+.[0-9]+*"
77

8+
permissions:
9+
contents: write
10+
id-token: write # This is required for requesting the JWT
11+
812
env:
913
# As defined by the Taskfile's PROJECT_NAME variable
1014
PROJECT_NAME: arduino-create-agent
@@ -47,9 +51,6 @@ jobs:
4751

4852
runs-on: ${{ matrix.os }}
4953
environment: production
50-
permissions:
51-
contents: write
52-
id-token: write # This is required for requesting the JWT
5354

5455
steps:
5556
- name: Set env vars
@@ -236,9 +237,6 @@ jobs:
236237
GON_PATH: ${{ github.workspace }}/gon
237238
needs: [build, create-macos-bundle]
238239
environment: production
239-
permissions:
240-
contents: write
241-
id-token: write # This is required for requesting the JWT
242240

243241
steps:
244242
- name: Download artifact
@@ -545,9 +543,6 @@ jobs:
545543
runs-on: ubuntu-20.04
546544
environment: production
547545
needs: [build, package, generate-sign-dmg]
548-
permissions:
549-
contents: write
550-
id-token: write # This is required for requesting the JWT
551546

552547
steps:
553548
- name: Checkout

0 commit comments

Comments
 (0)