]> git.ipfire.org Git - thirdparty/pdns.git/commitdiff
builder-dispatch: Explicitly grant id-token: write to the build package workflow 12979/head
authorRemi Gacogne <remi.gacogne@powerdns.com>
Mon, 3 Jul 2023 13:28:21 +0000 (15:28 +0200)
committerRemi Gacogne <remi.gacogne@powerdns.com>
Mon, 3 Jul 2023 13:42:34 +0000 (15:42 +0200)
.github/workflows/builder-dispatch.yml

index 456af0af244f9b73350f8229d7fec5f433c84d23..30cab32c47f78a3b74a7ebfaa7ff65078741b3d0 100644 (file)
@@ -35,6 +35,11 @@ on:
         - 'NO'
         - 'YES'
 
+permissions: # least privileges, see https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
+  actions: read
+  contents: write # To be able to upload assets as release artifacts
+  id-token: write # To sign the provenance in the build packages reusable workflow.
+
 jobs:
   call-build-packages:
     uses: PowerDNS/pdns/.github/workflows/build-packages.yml@master