Skip to content

Commit 1884b69

Browse files
committed
actions: add some missing permissions
Also adjust the comments for actions that do not need permissions
1 parent 03ce2b0 commit 1884b69

File tree

1 file changed

+7
-4
lines changed

1 file changed

+7
-4
lines changed

actions/ql/lib/ext/config/actions_permissions.yml

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,10 @@ extensions:
1313
- ["actions/labeler", "pull-requests: write"]
1414
- ["actions/attest", "id-token: write"]
1515
- ["actions/attest", "attestations: write"]
16-
# No permissions needed for actions/add-to-project
16+
- ["actions/add-to-project", "repository-projects:read"]
17+
- ["actions/add-to-project", "repository-projects:write"]
18+
- ["actions/add-to-project", "issues:read"]
19+
- ["actions/add-to-project", "pull-requests:read"]
1720
- ["actions/dependency-review-action", "contents: read"]
1821
- ["actions/attest-sbom", "id-token: write"]
1922
- ["actions/attest-sbom", "attestations: write"]
@@ -30,8 +33,8 @@ extensions:
3033
- ["actions/versions-package-tools", "actions: read"]
3134
- ["actions/reusable-workflows", "contents: read"]
3235
- ["actions/reusable-workflows", "actions: read"]
33-
# TODO: Add permissions for actions/download-artifact
34-
# TODO: Add permissions for actions/upload-artifact
35-
# TODO: Add permissions for actions/cache
36+
# No permissions needed for actions/download-artifact
37+
# No permissions needed for actions/upload-artifact
38+
# No permissions needed for actions/cache
3639

3740

0 commit comments

Comments
 (0)