Skip to content

[CI][OSSF] Add default permissions to work flows #13173

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged

Conversation

stdale-intel
Copy link
Contributor

per OSSF (https://securityscorecards.dev/viewer/?uri=github.com/intel/llvm) all workflows should have default top level permission set. Which we set to below as per recommendation

permissions:
contents: read

then within actual jobs, when needed, we added additional privileges.

These changes were generated by the recommended OSSF tool

This PR changes those workflows created/owned by intel/llvm repo. Will do seperate PR for issues found in llvm/llvm-project inherited workflows.

@stdale-intel stdale-intel requested a review from a team as a code owner March 27, 2024 04:50
Copy link
Contributor

@aelovikov-intel aelovikov-intel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks reasonable to me but I encourage others to look at it as well.

@stdale-intel
Copy link
Contributor Author

stdale-intel commented Mar 27, 2024

@intel/llvm-gatekeepers this should be good to go since failure is unrelated

FAILED: lib/libLLVMAMDGPUCodeGen.so.19.0git

@aelovikov-intel aelovikov-intel merged commit 1e894d1 into intel:sycl Mar 28, 2024
@aarongreig
Copy link
Contributor

aelovikov-intel pushed a commit that referenced this pull request Apr 2, 2024
After #13173 , we are not able to push
container images.
See
https://github.com/intel/llvm/actions/runs/8485593107/job/23250649681

```
------
 > pushing ghcr.io/intel/llvm/ubuntu2204_base:2f03ef85fee5e867c8250d535f561f2e52e5260c with docker:
------
ERROR: denied: installation not allowed to Write organization package
Error: buildx failed with: ERROR: denied: installation not allowed to Write organization package
```

We need to update the docker images, so need to write packages.

Push permission tested through non PR workflow run here:
https://github.com/intel/llvm/actions/runs/8516878870
aelovikov-intel added a commit to aelovikov-intel/llvm that referenced this pull request May 6, 2024
jsji added a commit that referenced this pull request May 7, 2024
The update_check started to fail 2 weeks ago in https://github.com/intel/llvm/actions/runs/8461500755.

Last CUDA e2e success was https://github.com/intel/llvm/actions/runs/8460746056 2 weeks ago!!
So looks like a problem caused by #13173 again..
aelovikov-intel pushed a commit that referenced this pull request May 7, 2024
The update-check started to fail 2 months ago in
https://github.com/intel/llvm/actions/runs/8461500755.

Last CUDA e2e success was
https://github.com/intel/llvm/actions/runs/8460746056 2 months ago!!
So looks like a problem caused by #13173 again..
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants