Skip to content

Commit 7a8df7c

Browse files
mesh-2092 move permissions from workflow level to job level
1 parent f559103 commit 7a8df7c

2 files changed

Lines changed: 20 additions & 10 deletions

File tree

.github/workflows/merge-develop.yml

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,13 @@ on:
44
branches:
55
- develop
66

7-
permissions:
8-
contents: write
9-
checks: write
10-
pull-requests: write
11-
127
jobs:
138
coverage:
149
runs-on: ubuntu-latest
10+
permissions:
11+
contents: write
12+
checks: write
13+
pull-requests: write
1514
if: github.repository == 'NHSDigital/mesh-sandbox' && !contains(github.event.head_commit.message, 'tag release version:')
1615
steps:
1716
- name: checkout
@@ -110,6 +109,10 @@ jobs:
110109

111110
publish:
112111
runs-on: ubuntu-latest
112+
permissions:
113+
contents: write
114+
checks: write
115+
pull-requests: write
113116
if: github.repository == 'NHSDigital/mesh-sandbox' && github.actor != 'dependabot[bot]' && !contains(github.event.head_commit.message, 'tag release version:')
114117
steps:
115118
- name: checkout

.github/workflows/pull-request.yml

Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,14 +4,13 @@ on:
44
branches:
55
- develop
66

7-
permissions:
8-
contents: write
9-
checks: write
10-
pull-requests: write
11-
127
jobs:
138
coverage:
149
runs-on: ubuntu-latest
10+
permissions:
11+
contents: write
12+
checks: write
13+
pull-requests: write
1514
if: github.repository == 'NHSDigital/mesh-sandbox'
1615
steps:
1716
- name: checkout
@@ -152,6 +151,10 @@ jobs:
152151

153152
lint:
154153
runs-on: ubuntu-latest
154+
permissions:
155+
contents: write
156+
checks: write
157+
pull-requests: write
155158
if: github.repository == 'NHSDigital/mesh-sandbox'
156159
steps:
157160
- name: checkout
@@ -231,6 +234,10 @@ jobs:
231234

232235
publish:
233236
runs-on: ubuntu-latest
237+
permissions:
238+
contents: write
239+
checks: write
240+
pull-requests: write
234241
if: github.repository == 'NHSDigital/mesh-sandbox' && github.actor != 'dependabot[bot]'
235242
needs:
236243
- coverage

0 commit comments

Comments
 (0)