Skip to content

Commit 685f749

Browse files
authored
Add perms and pins to github actions (#612)
1 parent 4c9a554 commit 685f749

File tree

3 files changed

+21
-13
lines changed

3 files changed

+21
-13
lines changed

.github/workflows/check-license.yml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,19 +2,20 @@ name: License Header Check
22

33
on:
44
pull_request:
5-
branches:
6-
- develop
75
push:
86
branches:
97
- develop
108

9+
permissions:
10+
contents: read
11+
1112
jobs:
1213
check-license-header:
1314
name: Check License Header
1415
runs-on: ubuntu-latest
1516
steps:
16-
- uses: actions/checkout@v6
17+
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
1718

18-
- uses: apache/skywalking-eyes/header@main
19+
- uses: apache/skywalking-eyes/header@b7f8b351c2db8005972712d7efc0a15484a15bcb
1920
with:
2021
mode: check

.github/workflows/ci.yml

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
name: CI
22

33
on:
4+
pull_request:
45
push:
56
branches:
67
- develop
78
- main
89

9-
pull_request:
10-
branches:
11-
- develop
10+
permissions:
11+
contents: read
1212

1313
jobs:
1414
ci:
@@ -20,19 +20,19 @@ jobs:
2020

2121
steps:
2222
- name: Checkout Repository
23-
uses: actions/checkout@v6
23+
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
2424

2525
- name: Set up JDK 17
26-
uses: actions/setup-java@v5
26+
uses: actions/setup-java@dded0888837ed1f317902acf8a20df0ad188d165
2727
with:
2828
java-version: 17
2929
distribution: 'corretto'
3030

3131
- name: Setup Gradle
32-
uses: gradle/actions/setup-gradle@v5
32+
uses: gradle/actions/setup-gradle@4d9f0ba0025fe599b4ebab900eb7f3a1d93ef4c2
3333

3434
- name: Install uv and set the Python version
35-
uses: astral-sh/setup-uv@v7
35+
uses: astral-sh/setup-uv@1e862dfacbd1d6d858c55d9b792c756523627244
3636
with:
3737
python-version: ${{ matrix.python-version }}
3838
activate-environment: true

.github/workflows/update-gradle-wrapper.yml

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,14 +7,21 @@ on:
77
# Run at midnight (UTC) every wednesday
88
- cron: "0 0 * * 3"
99

10+
permissions:
11+
contents: read
12+
1013
jobs:
1114
update-gradle-wrapper:
1215
runs-on: ubuntu-latest
1316

17+
permissions:
18+
# allow job to open a pull request with changes
19+
pull-requests: write
20+
1421
steps:
15-
- uses: actions/checkout@v6
22+
- uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3
1623

1724
- name: Update Gradle Wrapper
18-
uses: gradle-update/update-gradle-wrapper-action@v2
25+
uses: gradle-update/update-gradle-wrapper-action@512b1875f3b6270828abfe77b247d5895a2da1e5
1926
with:
2027
paths: codegen/**

0 commit comments

Comments
 (0)