Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/workflows/benchmark.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,13 @@ concurrency:
group: benchmark-${{ github.ref }}
cancel-in-progress: true

permissions: read-all

jobs:
benchmark:
permissions:
contents: read
pull-requests: write # Post the benchmark report on the PR.
runs-on: ubuntu-large
steps:
- name: Checkout
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/bypass.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ name: build
on:
workflow_dispatch:

permissions: read-all

jobs:
reset-run-number:
runs-on: ubuntu-latest
Expand All @@ -17,6 +19,12 @@ jobs:
run-id: ${{ github.run_number }}

pr-merged:
permissions:
contents: write # Create the release.
id-token: write # Sign images and attest provenance.
pull-requests: write # Required by the nested benchmark workflow.
artifact-metadata: write # Create the attested image storage record.
attestations: write
needs: reset-run-number
uses: ./.github/workflows/incluster-comp-pr-merged.yaml
with:
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/check-ig-pin.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ on:
- "scripts/check-inspektor-gadget-pin.sh"
- ".github/workflows/check-ig-pin.yaml"

permissions: read-all

jobs:
check:
name: check-ig-pin
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/component-tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions: read-all

jobs:
build-and-push-image:
runs-on: ubuntu-latest
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/go-basic-tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -36,8 +36,11 @@ on:
GITGUARDIAN_API_KEY:
required: false

permissions: read-all

jobs:
Check-secret:
permissions: {}
name: check if secrets are set
runs-on: ubuntu-latest
outputs:
Expand Down Expand Up @@ -69,6 +72,10 @@ jobs:
# fi

Environment-Test:
permissions:
contents: read
actions: read
security-events: write # Upload CodeQL results.
name: Create cross-platform build
# needs: [ Setup-Environment ]
runs-on: ubuntu-latest
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/incluster-comp-pr-created.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -33,11 +33,14 @@ on:
GITGUARDIAN_API_KEY:
required: false

permissions: read-all

jobs:
test:
permissions:
pull-requests: write
security-events: write
contents: read
actions: read
security-events: write # Pass CodeQL permissions to the test workflow.
uses: ./.github/workflows/go-basic-tests.yaml
with:
GO_VERSION: ${{ inputs.GO_VERSION }}
Expand Down
9 changes: 7 additions & 2 deletions .github/workflows/incluster-comp-pr-merged.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,8 @@ on:
default: false
type: boolean

permissions: read-all

jobs:
docker-build:
if: ${{ ((contains(github.event.pull_request.labels.*.name, 'release') || contains( github.event.pull_request.labels.*.name, 'trigger-integration-test')) && github.repository_owner == 'kubescape') || inputs.FORCE }}
Expand All @@ -69,9 +71,8 @@ jobs:
TEST_NAMES: ${{ steps.export_tests_to_env.outputs.TEST_NAMES }}
permissions:
id-token: write
packages: write
contents: read
pull-requests: read
artifact-metadata: write # Create the attested image storage record.
attestations: write # required by actions/attest-build-provenance

steps:
Expand Down Expand Up @@ -172,6 +173,7 @@ jobs:
input: ${{ inputs.REQUIRED_TESTS }}

run-tests:
permissions: {} # Private-repository operations use the GitHub App token.
needs: docker-build
if: ${{ inputs.HELM_E2E_TEST == true }}
runs-on: ubuntu-latest
Expand Down Expand Up @@ -346,6 +348,9 @@ jobs:
retention-days: 7

benchmark:
permissions:
contents: read
pull-requests: write # Required by the reusable benchmark workflow.
needs: docker-build
if: ${{ contains(github.event.pull_request.labels.*.name, 'release') }}
uses: ./.github/workflows/benchmark.yaml
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/pr-created.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,14 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions: read-all

jobs:
pr-created:
permissions:
contents: read
actions: read
security-events: write # Pass CodeQL permissions through nested workflows.
uses: ./.github/workflows/incluster-comp-pr-created.yaml
with:
GO_VERSION: "1.27"
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/pr-merged.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ on:

workflow_dispatch:

permissions: read-all

jobs:
reset-run-number:
runs-on: ubuntu-latest
Expand All @@ -28,11 +30,10 @@ jobs:
if: ${{ github.event.pull_request.merged == true }} ## Skip if not merged
needs: reset-run-number
permissions:
actions: read
id-token: write
packages: write
contents: write
pull-requests: read
pull-requests: write # Required by the nested benchmark workflow.
artifact-metadata: write # Create the attested image storage record.
attestations: write # required by actions/attest-build-provenance in the shared workflow
uses: ./.github/workflows/incluster-comp-pr-merged.yaml
with:
Expand Down
Loading