Skip to content

gh: aligned workflow permissions with smallstep/workflows#324#1631

Merged
azazeal merged 1 commit into
masterfrom
panos/workflows
May 20, 2026
Merged

gh: aligned workflow permissions with smallstep/workflows#324#1631
azazeal merged 1 commit into
masterfrom
panos/workflows

Conversation

@azazeal
Copy link
Copy Markdown
Contributor

@azazeal azazeal commented May 20, 2026

This PR amends the workflows configuration to be more inline with smallstep/workflows#324.

It additionally addresses the following:

  1. Relaxes the dependabot-auto-merge.yml permissions, since the called workflow no longer needs contents: write or pull-requests: write.
  2. Drops pull-requests: write from triage.yml, since the called workflow only labels via the issues API.
  3. Relaxes contents: write to contents: read on the build_upload_docker and build_upload_docker_debian jobs in release.yml.

@github-actions github-actions Bot added the needs triage Waiting for discussion / prioritization by team label May 20, 2026
@azazeal azazeal marked this pull request as ready for review May 20, 2026 14:06
@azazeal azazeal enabled auto-merge May 20, 2026 14:06
@hslatman hslatman added this to the v0.30.3 milestone May 20, 2026
@azazeal azazeal merged commit 5746dd2 into master May 20, 2026
28 checks passed
@azazeal azazeal deleted the panos/workflows branch May 20, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs triage Waiting for discussion / prioritization by team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants