forked from open-telemetry/opentelemetry-java-examples
    
        
        - 
                Notifications
    
You must be signed in to change notification settings  - Fork 0
 
Closed
Description
notes:
- use 
permissions: contents: readinstead ofpermissions: read-all, unless the workflow is already usingpermissions: read-allin which case leave it be - make sure that each workflow job that needs elevated permissions declares the permissions it needs
- if it needs a job-specific permission block but doesn't have one already add it at the top of the job (don't re-order existing blocks)
 - don't include contents: read in these job-specific blocks since the repos are already public
 
 - remember elevated token permissions for a specific step aren't needed when 
OPENTELEMETRYBOT_GITHUB_TOKENis used for that step - remember 
actions/cache/savedoesn't need any permissions - remember 
JamesIves/github-pages-deploy-actionneedscontents: writepermission - there's no need to verify local build after making changes to the workflow files, since they aren't used during a local build anyways
 - don't make unnecessary changes to the workflow files, only add the missing permissions
 
related to https://scorecard.dev/viewer/?uri=github.com/open-telemetry/opentelemetry-java-examples
Copilot
Metadata
Metadata
Assignees
Labels
No labels