fix: narrow down action permissions to per-job ones

This commit is contained in:
Stavros
2026-04-29 16:41:24 +03:00
parent 956d2f55c3
commit 44c763c302
4 changed files with 40 additions and 8 deletions
+15 -2
View File
@@ -6,8 +6,7 @@ on:
- "v*"
permissions:
contents: write
packages: write
contents: read
jobs:
generate-metadata:
@@ -117,6 +116,8 @@ jobs:
runs-on: ubuntu-latest
needs:
- generate-metadata
permissions:
packages: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -172,6 +173,8 @@ jobs:
needs:
- generate-metadata
- image-build
permissions:
packages: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -227,6 +230,8 @@ jobs:
runs-on: ubuntu-24.04-arm
needs:
- generate-metadata
permissions:
packages: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -282,6 +287,8 @@ jobs:
needs:
- generate-metadata
- image-build-arm
permissions:
packages: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -338,6 +345,8 @@ jobs:
needs:
- image-build
- image-build-arm
permissions:
packages: write
steps:
- name: Download digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
@@ -379,6 +388,8 @@ jobs:
needs:
- image-build-distroless
- image-build-arm-distroless
permissions:
packages: write
steps:
- name: Download digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
@@ -422,6 +433,8 @@ jobs:
needs:
- binary-build
- binary-build-arm
permissions:
contents: write
steps:
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with: