From 92bdbb2f57d674763242db4a9649ef44ead3309d Mon Sep 17 00:00:00 2001 From: Etienne Stalmans Date: Tue, 10 Mar 2026 14:47:26 +0100 Subject: [PATCH] chore: explicit permissions on actions (#43526) enforces minimal set of permissions, the same as other actions in the repo --- .github/workflows/docs-js-libs-update.yml | 9 ++++++--- .github/workflows/publish_image.yml | 3 +++ .github/workflows/trigger-nimbus-sync.yml | 3 +++ .github/workflows/update-js-libs.yml | 14 ++++++++------ .github/workflows/validate-pr.yml | 3 +++ 5 files changed, 23 insertions(+), 9 deletions(-) diff --git a/.github/workflows/docs-js-libs-update.yml b/.github/workflows/docs-js-libs-update.yml index 398ebf0b5fb..9f94c4addbb 100644 --- a/.github/workflows/docs-js-libs-update.yml +++ b/.github/workflows/docs-js-libs-update.yml @@ -42,10 +42,13 @@ jobs: - name: Regenerate JS client libraries tsdoc files working-directory: apps/docs/spec + env: + SOURCE: ${{ github.event.inputs.source }} + VERSION: ${{ github.event.inputs.version }} run: | echo "Regenerating tsdoc files for JS client libraries..." - echo "Source: ${{ github.event.inputs.source }}" - echo "Version: ${{ github.event.inputs.version }}" + echo "Source: ${SOURCE}" + echo "Version: ${VERSION}" make - name: Generate new typespec snapshot @@ -68,7 +71,7 @@ jobs: commit-message: 'docs: update js sdk docs (${{ github.event.inputs.version }})' title: 'docs: update js sdk docs (${{ github.event.inputs.version }})' body: | - Updates JS sdk documentation following stable release. + Updates JS sdk documentation following stable release. Ran `make` in apps/docs/spec to regenerate tsdoc files. **Details:** diff --git a/.github/workflows/publish_image.yml b/.github/workflows/publish_image.yml index 9865b284630..10143775f32 100644 --- a/.github/workflows/publish_image.yml +++ b/.github/workflows/publish_image.yml @@ -6,6 +6,9 @@ on: - cron: '0 4 * * 1' workflow_dispatch: +permissions: + contents: read + jobs: settings: runs-on: blacksmith-4vcpu-ubuntu-2404 diff --git a/.github/workflows/trigger-nimbus-sync.yml b/.github/workflows/trigger-nimbus-sync.yml index 8e47cc31e5c..082e15905fe 100644 --- a/.github/workflows/trigger-nimbus-sync.yml +++ b/.github/workflows/trigger-nimbus-sync.yml @@ -5,6 +5,9 @@ on: branches: [master] workflow_dispatch: # Allow manual triggering +permissions: + contents: read + jobs: trigger-nimbus-sync: runs-on: ubuntu-latest diff --git a/.github/workflows/update-js-libs.yml b/.github/workflows/update-js-libs.yml index ef6a611e712..3fea336ff5c 100644 --- a/.github/workflows/update-js-libs.yml +++ b/.github/workflows/update-js-libs.yml @@ -38,32 +38,34 @@ jobs: cache: 'pnpm' - name: Update @supabase/*-js packages in pnpm-workspace.yaml + env: + VERSION: ${{ github.event.inputs.version }} run: | # Update @supabase/supabase-js - sed -i "s/'@supabase\/supabase-js': .*/'@supabase\/supabase-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml + sed -i "s|'@supabase/supabase-js': .*|'@supabase/supabase-js': ${VERSION}|" pnpm-workspace.yaml # Update @supabase/auth-js - sed -i "s/'@supabase\/auth-js': .*/'@supabase\/auth-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml + sed -i "s|'@supabase/auth-js': .*|'@supabase/auth-js': ${VERSION}|" pnpm-workspace.yaml # Update @supabase/realtime-js - sed -i "s/'@supabase\/realtime-js': .*/'@supabase\/realtime-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml + sed -i "s|'@supabase/realtime-js': .*|'@supabase/realtime-js': ${VERSION}|" pnpm-workspace.yaml # Update @supabase/postgrest-js - sed -i "s/'@supabase\/postgrest-js': .*/'@supabase\/postgrest-js': ${{ github.event.inputs.version }}/" pnpm-workspace.yaml + sed -i "s|'@supabase/postgrest-js': .*|'@supabase/postgrest-js': ${VERSION}|" pnpm-workspace.yaml echo "Updated pnpm-workspace.yaml:" cat pnpm-workspace.yaml - name: Install dependencies run: pnpm install --no-frozen-lockfile - + - name: Generate token id: app-token uses: actions/create-github-app-token@29824e69f54612133e76f7eaac726eef6c875baf # v2.2.1 with: app-id: ${{ secrets.GH_AUTOFIX_APP_ID }} private-key: ${{ secrets.GH_AUTOFIX_PRIVATE_KEY }} - + - name: Create pull request uses: peter-evans/create-pull-request@c5a7806660adbe173f04e3e038b0ccdcd758773c # v6.1.0 with: diff --git a/.github/workflows/validate-pr.yml b/.github/workflows/validate-pr.yml index ffb9c43ca95..af68e012b3d 100644 --- a/.github/workflows/validate-pr.yml +++ b/.github/workflows/validate-pr.yml @@ -5,6 +5,9 @@ on: pull_request: types: [opened, labeled, unlabeled, synchronize, ready_for_review] +permissions: + contents: read + jobs: validate-pr: runs-on: ubuntu-latest