Signed-off-by: Varun Sharma <varunsh@stepsecurity.io>
Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Paul Dale <pauli@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/18766)
15 files changed:
# before_script:
# - make="make -s"
+permissions:
+ contents: read
+
jobs:
check_update:
runs-on: ubuntu-latest
on: [push]
+permissions:
+ contents: read
+
jobs:
compiler:
strategy:
schedule:
- cron: '49 0 * * *'
+permissions:
+ contents: read
+
jobs:
coverage:
+ permissions:
+ checks: write # for coverallsapp/github-action to create new checks
+ contents: read # for actions/checkout to fetch code
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
on: [pull_request, push]
+permissions:
+ contents: read
+
jobs:
cross-compilation:
strategy:
name: FIPS Checksums
on: [pull_request]
+permissions:
+ contents: read
+
jobs:
compute-checksums:
runs-on: ubuntu-latest
types:
- completed
+permissions:
+ contents: read
+
jobs:
apply-label:
+ permissions:
+ actions: read
+ pull-requests: write
runs-on: ubuntu-latest
if: ${{ github.event.workflow_run.event == 'pull_request' }}
steps:
name: Provider compat
on: [push]
+permissions:
+ contents: read
+
jobs:
fips-provider-30:
runs-on: ubuntu-latest
on: [push]
+permissions:
+ contents: read
+
jobs:
fuzz-checker:
strategy:
name: CIFuzz
on: [pull_request, push]
+permissions:
+ contents: read
+
jobs:
Fuzzing:
runs-on: ubuntu-latest
schedule:
- cron: '0 5 * * *'
+permissions:
+ contents: read
+
jobs:
unix:
strategy:
# Jobs run per pull request submission
name: Run-checker CI
on: [pull_request, push]
+permissions:
+ contents: read
+
jobs:
run-checker:
strategy:
on:
schedule:
- cron: '0 6 * * *'
+permissions:
+ contents: read
+
jobs:
run-checker:
strategy:
# Jobs run per merge to master
on: [push]
+permissions:
+ contents: read
+
jobs:
run-checker:
strategy:
schedule:
- cron: '20 0 * * *'
+permissions:
+ contents: read
+
jobs:
coverity:
runs-on: ubuntu-latest
on: [pull_request, push]
+permissions:
+ contents: read
+
jobs:
shared:
# Run a job for each of the specified target architectures: