From c2ddacf2e5d4bb7a53f8c97640a7be505eebe12d Mon Sep 17 00:00:00 2001 From: Neal Beeken Date: Wed, 19 Jul 2023 16:45:46 -0400 Subject: [PATCH 1/2] chore(NODE-5474): move id-token permission to workflow --- .github/workflows/release-4.x.yml | 3 +-- .github/workflows/release-alpha.yml | 5 +++-- .github/workflows/release-nightly.yml | 6 ++++-- .github/workflows/release.yml | 3 +-- 4 files changed, 9 insertions(+), 8 deletions(-) diff --git a/.github/workflows/release-4.x.yml b/.github/workflows/release-4.x.yml index 5735a86dbb3..dcda4e2d822 100644 --- a/.github/workflows/release-4.x.yml +++ b/.github/workflows/release-4.x.yml @@ -6,14 +6,13 @@ on: permissions: contents: write pull-requests: write + id-token: write name: release-4x jobs: release-please: runs-on: ubuntu-latest - permissions: - id-token: write steps: - id: release uses: google-github-actions/release-please-action@v3 diff --git a/.github/workflows/release-alpha.yml b/.github/workflows/release-alpha.yml index 73abc2a957e..937ba537f2f 100644 --- a/.github/workflows/release-alpha.yml +++ b/.github/workflows/release-alpha.yml @@ -8,13 +8,14 @@ on: required: true type: string +permissions: + id-token: write + name: release-alpha jobs: release-alpha: runs-on: ubuntu-latest - permissions: - id-token: write steps: - shell: bash run: | diff --git a/.github/workflows/release-nightly.yml b/.github/workflows/release-nightly.yml index 4409562cc56..66ff50f9bf3 100644 --- a/.github/workflows/release-nightly.yml +++ b/.github/workflows/release-nightly.yml @@ -11,13 +11,15 @@ on: # As long as the commit hash has changed on main a release will be published workflow_dispatch: {} +permissions: + id-token: write + name: release-nightly jobs: release-nightly: runs-on: ubuntu-latest - permissions: - id-token: write + steps: - uses: actions/checkout@v3 - name: actions/setup diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2eefa9848c2..7cc1ca92af0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,14 +6,13 @@ on: permissions: contents: write pull-requests: write + id-token: write name: release jobs: release-please: runs-on: ubuntu-latest - permissions: - id-token: write steps: - id: release uses: google-github-actions/release-please-action@v3 From 0d1150eb1899d4263218c7f232db6a3d8017a1a9 Mon Sep 17 00:00:00 2001 From: Neal Beeken Date: Thu, 20 Jul 2023 16:14:22 -0400 Subject: [PATCH 2/2] hotfix: newline --- .github/workflows/release-nightly.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/release-nightly.yml b/.github/workflows/release-nightly.yml index 66ff50f9bf3..0be13e3c125 100644 --- a/.github/workflows/release-nightly.yml +++ b/.github/workflows/release-nightly.yml @@ -19,7 +19,6 @@ name: release-nightly jobs: release-nightly: runs-on: ubuntu-latest - steps: - uses: actions/checkout@v3 - name: actions/setup