Skip to content

Commit f3a5cab

Browse files
committed
add permissions, fixes #172
1 parent 241c355 commit f3a5cab

File tree

4 files changed

+23
-5
lines changed

4 files changed

+23
-5
lines changed

.github/dependabot.yml

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,5 +3,13 @@ updates:
33
- package-ecosystem: "maven"
44
directory: "/"
55
schedule:
6-
interval: "daily"
7-
open-pull-requests-limit: 10
6+
interval: daily
7+
open-pull-requests-limit: 30
8+
labels: [ "Type: dependencies" ]
9+
10+
- package-ecosystem: "github-actions"
11+
directory: "/"
12+
schedule:
13+
interval: daily
14+
open-pull-requests-limit: 30
15+
labels: [ "Type: dependencies" ]

.github/workflows/development.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
11
name: Development branches
22

3+
permissions:
4+
contents: read
5+
36
on:
47
push:
58
pull_request:

.github/workflows/master.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
11
name: Produces and releases artifacts
22

3+
permissions:
4+
contents: read
5+
36
on:
47
push:
58
branches:
@@ -41,10 +44,11 @@ jobs:
4144

4245
# Publish release
4346
- name: Deploy a new release version to Maven Central
44-
run: ./mvnw clean deploy -B -ntp -DskipTests -DskipExamples -Prelease -Dgpg.keyname="${{ secrets.GPG_KEYNAME }}" -Dgpg.passphrase="${{ secrets.GPG_PASSPHRASE }}"
47+
run: ./mvnw clean deploy -B -ntp -DskipTests -DskipExamples -Prelease -Dgpg.keyname="${{ secrets.GPG_KEYNAME }}"
4548
env:
4649
OSS_CENTRAL_USERNAME: ${{ secrets.SONATYPE_USERNAME }}
4750
OSS_CENTRAL_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }}
51+
MAVEN_GPG_PASSPHRASE: "${{ secrets.GPG_PASSPHRASE }}"
4852

4953
# - name: Upload coverage information
5054
# uses: codecov/codecov-action@v2

.github/workflows/release-notes.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,11 @@
1-
# Trigger the workflow on milestone events
1+
name: Milestone Closure
2+
3+
permissions:
4+
contents: read
5+
26
on:
37
milestone:
48
types: [closed]
5-
name: Milestone Closure
69
jobs:
710
create-release-notes:
811
runs-on: ubuntu-latest

0 commit comments

Comments
 (0)