fix: review actions (#34648)

* fix: possible command injection in docs-lint

* fix: explicit permissions for github actions
This commit is contained in:
Stephen Morgan authored and GitHub committed 2025-04-02 16:41:14 +13:00
1 parent ab73c916c1
commit 431be5682b
20 files changed
+67 -3

No files matched your search

+3
View File
@@ -17,6 +17,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
+5
View File
@@ -10,9 +10,14 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
autofix:
runs-on: ubuntu-latest
permissions:
contents: write
if: ${{ github.event_name == 'pull_request' && (github.event.label.name == 'autofix') }}
steps:
- name: Calculate number of commits
+3
View File
@@ -8,6 +8,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
misspell:
name: runner / misspell
+3
View File
@@ -10,6 +10,9 @@ on:
required: false
type: boolean
permissions:
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
+3 -3
View File
@@ -54,7 +54,7 @@ jobs:
REVIEWDOG_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -o pipefail
git diff --name-only origin/$BASE_REF HEAD \
git diff --name-only "origin/$BASE_REF" HEAD \
| { grep -E "^apps/docs/content/" || test $? = 1; } \
| xargs -r supa-mdx-lint --format rdf \
| reviewdog -f=rdjsonl -reporter=github-pr-review -tee
@@ -67,7 +67,7 @@ jobs:
run: |
set -o pipefail
run_lints() {
git diff --name-only origin/$BASE_REF HEAD \
git diff --name-only "origin/$BASE_REF" HEAD \
| { grep -E "^apps/docs/content/" || test $? = 1; } \
| xargs -rx -n 1000000000 supa-mdx-lint --format markdown
}
@@ -76,6 +76,6 @@ jobs:
LINT_EXIT_CODE=$?
set -e
if [[ $LINT_EXIT_CODE -ne 0 ]]; then
gh pr comment $BRANCH_NAME --body "$LINT_RESULTS"
gh pr comment "$BRANCH_NAME" --body "$LINT_RESULTS"
exit 1
fi
@@ -6,6 +6,10 @@ on:
- cron: '0 0 * * 1'
workflow_dispatch:
permissions:
pull-requests: write
contents: read
jobs:
update-docs:
runs-on: ubuntu-latest
+3
View File
@@ -11,6 +11,9 @@ concurrency:
group: ${{ github.workflow }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
+3
View File
@@ -11,6 +11,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
+4
View File
@@ -9,6 +9,10 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
pull-requests: write
jobs:
build:
runs-on: ubuntu-latest
+3
View File
@@ -8,6 +8,9 @@ on:
- 'supabase/functions/og-images/**'
workflow_dispatch:
permissions:
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
+4
View File
@@ -15,6 +15,10 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
id-token: write
jobs:
build:
runs-on: ubuntu-latest
+3
View File
@@ -10,6 +10,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
format:
runs-on: ubuntu-latest
+3
View File
@@ -17,6 +17,9 @@ on:
schedule:
- cron: '0 0 * * *'
permissions:
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
@@ -11,6 +11,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
+5
View File
@@ -3,6 +3,11 @@ on:
schedule:
- cron: '30 1 * * *'
permissions:
issues: write
pull-requests: write
contents: read
jobs:
build:
runs-on: ubuntu-latest
+3
View File
@@ -20,6 +20,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: write
jobs:
test:
timeout-minutes: 60
+3
View File
@@ -20,6 +20,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
check:
# Uses larger hosted runner as it significantly decreases build times
+3
View File
@@ -10,6 +10,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
typecheck:
# Uses larger hosted runner as it significantly decreases build times
+3
View File
@@ -11,6 +11,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
+3
View File
@@ -11,6 +11,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest