Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 12 additions & 4 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,16 +36,18 @@ concurrency:
group: docs-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read
pages: write
id-token: write
# Set default permission for all jobs to none. The Pages write grants live on
# deploy-docs alone — build-docs only reads the repo and uploads an artifact.
permissions: {}

jobs:
build-docs:
runs-on: ubuntu-latest
timeout-minutes: 30

permissions:
contents: read

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down Expand Up @@ -136,6 +138,12 @@ jobs:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}

# actions/deploy-pages needs pages:write to publish and id-token:write for
# the OIDC token it exchanges. It does not check the repository out.
permissions:
pages: write
id-token: write

steps:
- name: Deploy to GitHub Pages
id: deployment
Expand Down
19 changes: 14 additions & 5 deletions .github/workflows/documentation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,15 +16,18 @@ on:
- 'docs/**'
- '.github/workflows/documentation.yml'

permissions:
contents: read
pull-requests: write
# Set default permission for all jobs to none. Only preview-documentation posts
# the PR comment, so pull-requests:write lives there rather than build-wide.
permissions: {}

jobs:
build-documentation:
runs-on: ubuntu-latest
timeout-minutes: 40


permissions:
contents: read

steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down Expand Up @@ -78,7 +81,13 @@ jobs:
if: github.event_name == 'pull_request'
needs: build-documentation
runs-on: ubuntu-latest


# Posts the preview comment via actions/github-script. PR comments are issue
# comments, so pull-requests:write is what listComments/createComment need.
permissions:
contents: read
pull-requests: write

steps:
- name: Download documentation artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
Expand Down
11 changes: 11 additions & 0 deletions .github/workflows/engine-benchmarks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Set default permission for all jobs to none
permissions: {}

jobs:
smoke-ubuntu-latest:
# Smoke pack on the default GitHub runner. Goal: prove the harness +
Expand All @@ -42,6 +45,10 @@ jobs:
# runner, shared tenancy, no warmup steady-state.
runs-on: ubuntu-latest
timeout-minutes: 20

permissions:
contents: read

steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

Expand Down Expand Up @@ -92,6 +99,10 @@ jobs:
if: github.event_name == 'workflow_dispatch' || github.event_name == 'release'
runs-on: [self-hosted, linux, x86_64, skainet-bench-linux-x86]
timeout-minutes: 120

permissions:
contents: read

steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/java-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,11 +10,17 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Set default permission for all jobs to none
permissions: {}

jobs:
java-tests:
runs-on: ubuntu-latest
timeout-minutes: 30

permissions:
contents: read

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/native-cpu-multiarch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,9 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Set default permission for all jobs to none
permissions: {}

jobs:
native-build-test:
name: ${{ matrix.arch_label }}
Expand All @@ -53,6 +56,9 @@ jobs:
runs-on: ${{ matrix.os }}
timeout-minutes: 30

permissions:
contents: read

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
13 changes: 13 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,11 @@ on:
tags:
- '**'

# Set default permission for all jobs to none. Publishing authenticates to Maven
# Central and signs with GPG through repository secrets, which are independent of
# GITHUB_TOKEN — nothing here needs write access to the repository itself.
permissions: {}

jobs:
build-native:
name: native ${{ matrix.arch_label }}
Expand All @@ -49,6 +54,10 @@ jobs:
lib_name: skainet_kernels.dll
runs-on: ${{ matrix.os }}
timeout-minutes: 30

permissions:
contents: read

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down Expand Up @@ -91,6 +100,10 @@ jobs:
name: Release build and publish
needs: build-native
runs-on: macOS-latest

permissions:
contents: read

steps:
- name: Check out code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/schema-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,15 @@ on:
- 'skainet-lang/**'
- '.github/workflows/schema-validation.yml'

# Set default permission for all jobs to none
permissions: {}

jobs:
validate-schema:
runs-on: ubuntu-latest

permissions:
contents: read

steps:
- name: Checkout code
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/verify-poms.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,18 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

# Set default permission for all jobs to none
permissions: {}

jobs:
verify-poms:
name: Publish to Maven local and validate POM coordinates
runs-on: ubuntu-latest
timeout-minutes: 45

permissions:
contents: read

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
Loading