Skip to content

ci: Fix govulncheck permissions - #5326

Merged
crazy-max merged 1 commit into
moby:masterfrom
silvin-lubecki:fix-ci-govulncheck-permissions
Sep 12, 2024
Merged

crazy-max merged 1 commit into
moby:masterfrom
silvin-lubecki:fix-ci-govulncheck-permissions

Conversation

@silvin-lubecki

Copy link
Copy Markdown
Contributor

It needs at least content read to be able to checkout the repository.

… able to checkout the repository.

Signed-off-by: Silvin Lubecki <silvin.lubecki@docker.com>
@thaJeztah

Copy link
Copy Markdown
Member

Curious though; looking at merged PRs on master, it doesn't complain when checking out the code, or was it failing in other ways? https://github.com/moby/buildkit/actions/runs/10821255341/job/30022906774#step:2:253

@silvin-lubecki

Copy link
Copy Markdown
Contributor Author

Curious though; looking at merged PRs on master, it doesn't complain when checking out the code, or was it failing in other ways? https://github.com/moby/buildkit/actions/runs/10821255341/job/30022906774#step:2:253

That is because the repository is available publicly 😸

@thaJeztah

Copy link
Copy Markdown
Member

Oh!!! Gotcha. That's a good one; I know we also have private security forks of moby/moby and docker/cli to test security patches before release. I guess I should check if those should also be updated.

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants