Skip to content

Bump code_ownership and teams gem - #3

Merged
alexevanczuk merged 2 commits into
mainfrom
ae-update-teams-gem
Jun 14, 2022
Merged

Bump code_ownership and teams gem#3
alexevanczuk merged 2 commits into
mainfrom
ae-update-teams-gem

Conversation

@alexevanczuk

Copy link
Copy Markdown
Contributor

@alexevanczuk
alexevanczuk merged commit fb227e3 into main Jun 14, 2022
@alexevanczuk
alexevanczuk deleted the ae-update-teams-gem branch June 14, 2022 19:47
dduugg added a commit that referenced this pull request Aug 17, 2026
Resolves the three open `actions/missing-workflow-permissions` CodeQL
alerts (#1, #3, #4). Each is a single-job caller of a reusable workflow in
rubyatscale/shared-config, so the permissions block goes job-level, right
above `uses:`, matching the query_packwerk precedent. A caller's block is
the ceiling for the called workflow, so each grant covers exactly what the
callee does and nothing more.

- cd.yml -> contents: write. shared-config's cd.yml checks out with
  persisted credentials and runs discourse/publish-rubygems-action, which
  does `rake release` (a raw git push of the version tag), then
  `gh release create`. Anything less breaks the gem release.
- stale.yml -> issues: write + pull-requests: write. shared-config's
  stale.yml runs actions/stale, which comments on and closes both stale
  issues and stale PRs. The implicit read of repo contents still works
  without naming contents.
- triage.yml -> issues: write. shared-config's triage.yml only runs
  `gh issue edit --add-label triage`.

ci.yml already declares workflow-level `contents: read` and codeql.yml
already declares its own block, so both are left untouched.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant