Skip to content

Initial commit - #1

Merged
alexevanczuk merged 2 commits into
mainfrom
ae-initial-commit
May 9, 2022
Merged

Initial commit#1
alexevanczuk merged 2 commits into
mainfrom
ae-initial-commit

Conversation

@alexevanczuk

Copy link
Copy Markdown
Contributor

Intial extraction from Gusto's codebase

@alexevanczuk
alexevanczuk merged commit d4e790b into main May 9, 2022
@alexevanczuk
alexevanczuk deleted the ae-initial-commit branch May 9, 2022 22:17
dduugg added a commit that referenced this pull request Aug 17, 2026
Resolves the three open `actions/missing-workflow-permissions` CodeQL
alerts (#1, #3, #4). Each is a single-job caller of a reusable workflow in
rubyatscale/shared-config, so the permissions block goes job-level, right
above `uses:`, matching the query_packwerk precedent. A caller's block is
the ceiling for the called workflow, so each grant covers exactly what the
callee does and nothing more.

- cd.yml -> contents: write. shared-config's cd.yml checks out with
  persisted credentials and runs discourse/publish-rubygems-action, which
  does `rake release` (a raw git push of the version tag), then
  `gh release create`. Anything less breaks the gem release.
- stale.yml -> issues: write + pull-requests: write. shared-config's
  stale.yml runs actions/stale, which comments on and closes both stale
  issues and stale PRs. The implicit read of repo contents still works
  without naming contents.
- triage.yml -> issues: write. shared-config's triage.yml only runs
  `gh issue edit --add-label triage`.

ci.yml already declares workflow-level `contents: read` and codeql.yml
already declares its own block, so both are left untouched.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant