ci(deploy): top-level contents: read on the self-testing workflow#433
Open
arpitjain099 wants to merge 1 commit into
Open
ci(deploy): top-level contents: read on the self-testing workflow#433arpitjain099 wants to merge 1 commit into
arpitjain099 wants to merge 1 commit into
Conversation
Author
|
I have read the CLA Document and I hereby sign the CLA |
cd5b54b to
f183b7a
Compare
Author
|
Hi @ericclemmons, gentle ping on this. PR has been open for 4 days without review. I noticed you've been on the recent-merger side of recent merges in this repo. When you have a moment, would you mind giving it a quick look? No urgency. Happy to address any feedback. |
Author
|
Hello, Just checking in on this. Let me know if anything needs tweaking before it can be considered. Thanks! |
The self-testing workflow exercises wrangler-action against test-fixture Workers using `secrets.CLOUDFLARE_API_TOKEN` and `secrets.CLOUDFLARE_ACCOUNT_ID`. The default GITHUB_TOKEN is only used for checkout, so contents: read is sufficient. Matches the top-level permissions style already used in release.yml and semgrep.yml. Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
f183b7a to
85351f6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins the default
GITHUB_TOKENto read-only fordeploy.yml— the workflow that runs the action against test-fixture Workers on PR. All wrangler deploys/deletes usesecrets.CLOUDFLARE_API_TOKENandsecrets.CLOUDFLARE_ACCOUNT_ID, so the GitHub token only needs read access to the checkout.Lines up with the top-level permissions blocks already in
release.ymlandsemgrep.yml. YAML validated locally.