chore: explicit permissions on actions (#43526)

enforces minimal set of permissions, the same as other actions in the
repo
This commit is contained in:
Etienne Stalmans authored and GitHub committed 2026-03-10 14:47:26 +01:00
1 parent 7cadc12136
commit 92bdbb2f57
5 files changed
+23 -9

No files matched your search

+6 -3
View File
@@ -42,10 +42,13 @@ jobs:
- name: Regenerate JS client libraries tsdoc files
working-directory: apps/docs/spec
env:
SOURCE: ${{ github.event.inputs.source }}
VERSION: ${{ github.event.inputs.version }}
run: |
echo "Regenerating tsdoc files for JS client libraries..."
echo "Source: ${{ github.event.inputs.source }}"
echo "Version: ${{ github.event.inputs.version }}"
echo "Source: ${SOURCE}"
echo "Version: ${VERSION}"
make
- name: Generate new typespec snapshot
@@ -68,7 +71,7 @@ jobs:
commit-message: 'docs: update js sdk docs (${{ github.event.inputs.version }})'
title: 'docs: update js sdk docs (${{ github.event.inputs.version }})'
body: |
Updates JS sdk documentation following stable release.
Updates JS sdk documentation following stable release.
Ran `make` in apps/docs/spec to regenerate tsdoc files.
**Details:**
+3
View File
@@ -6,6 +6,9 @@ on:
- cron: '0 4 * * 1'
workflow_dispatch:
permissions:
contents: read
jobs:
settings:
runs-on: blacksmith-4vcpu-ubuntu-2404
@@ -5,6 +5,9 @@ on:
branches: [master]
workflow_dispatch: # Allow manual triggering
permissions:
contents: read
jobs:
trigger-nimbus-sync:
runs-on: ubuntu-latest
+8 -6
View File
@@ -38,32 +38,34 @@ jobs:
cache: 'pnpm'
- name: Update @supabase/*-js packages in pnpm-workspace.yaml
env:
VERSION: ${{ github.event.inputs.version }}
run: |
# Update @supabase/supabase-js
sed -i "s/'@supabase\/supabase-js': .*/'@supabase\/supabase-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml
sed -i "s|'@supabase/supabase-js': .*|'@supabase/supabase-js': ${VERSION}|" pnpm-workspace.yaml
# Update @supabase/auth-js
sed -i "s/'@supabase\/auth-js': .*/'@supabase\/auth-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml
sed -i "s|'@supabase/auth-js': .*|'@supabase/auth-js': ${VERSION}|" pnpm-workspace.yaml
# Update @supabase/realtime-js
sed -i "s/'@supabase\/realtime-js': .*/'@supabase\/realtime-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml
sed -i "s|'@supabase/realtime-js': .*|'@supabase/realtime-js': ${VERSION}|" pnpm-workspace.yaml
# Update @supabase/postgrest-js
sed -i "s/'@supabase\/postgrest-js': .*/'@supabase\/postgrest-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml
sed -i "s|'@supabase/postgrest-js': .*|'@supabase/postgrest-js': ${VERSION}|" pnpm-workspace.yaml
echo "Updated pnpm-workspace.yaml:"
cat pnpm-workspace.yaml
- name: Install dependencies
run: pnpm install --no-frozen-lockfile
- name: Generate token
id: app-token
uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1
with:
app-id: ${{ secrets.GH_AUTOFIX_APP_ID }}
private-key: ${{ secrets.GH_AUTOFIX_PRIVATE_KEY }}
- name: Create pull request
uses: peter-evans/create-pull-request@c5a7806660adbe173f04e3e038b0ccdcd758773c # v6.1.0
with:
+3
View File
@@ -5,6 +5,9 @@ on:
pull_request:
types: [opened, labeled, unlabeled, synchronize, ready_for_review]
permissions:
contents: read
jobs:
validate-pr:
runs-on: ubuntu-latest