Skip to content

ci: scope down GitHub Token permissions #2

ci: scope down GitHub Token permissions

ci: scope down GitHub Token permissions #2

Workflow file for this run

name: Pull Request Checks
on:
pull_request:
permissions:
contents: read
jobs:
call-integration-tests:

Check failure on line 10 in .github/workflows/pull.yml

View workflow run for this annotation

GitHub Actions / Pull Request Checks

Invalid workflow file

The workflow is not valid. .github/workflows/pull.yml (Line: 10, Col: 3): Error calling workflow 'aws/aws-dynamodb-encryption-python/.github/workflows/ci_integration.yml@e30d786f479d7e692ad138ca8fac16abe2917730'. The nested job 'test' is requesting 'id-token: write', but is only allowed 'id-token: none'.
name: Run Integration Tests
uses: ./.github/workflows/ci_integration.yml
call-static-analysis:
name: Run Static Analysis
uses: ./.github/workflows/ci_static-analysis.yaml
call-tests:
name: Run Tests
uses: ./.github/workflows/ci_tests.yaml
pr-ci-all-required:
if: always()
needs:
- call-integration-tests
- call-static-analysis
- call-tests
runs-on: ubuntu-22.04
steps:
- name: Verify all required jobs passed
uses: re-actors/alls-green@release/v1
with:
jobs: ${{ toJSON(needs) }}