fix(workflows): elevate GITHUB_TOKEN permissions when needed (#822)
I am not 100% sure I was able to fix all the cases in which we need higher permissions than the strict default. At least, I tried. It may be reasonable to make an interim release to check whether I successfully fixed all the cases. Ref issue: https://github.com/ooni/probe/issues/2154
This commit is contained in:
parent
9b08dcac3f
commit
5371c7f486
23 changed files with 75 additions and 52 deletions
7
.github/workflows/gosec.yml
vendored
7
.github/workflows/gosec.yml
vendored
|
|
@ -1,12 +1,12 @@
|
|||
# runs gosec security scanner
|
||||
# Runs the gosec security scanner
|
||||
name: gosec
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- "master"
|
||||
- "release/**"
|
||||
jobs:
|
||||
|
||||
jobs:
|
||||
gosec:
|
||||
runs-on: ubuntu-20.04
|
||||
env:
|
||||
|
|
@ -18,8 +18,9 @@ jobs:
|
|||
steps:
|
||||
- name: Checkout Source
|
||||
uses: actions/checkout@v2
|
||||
|
||||
- name: Run Gosec security scanner
|
||||
continue-on-error: true
|
||||
continue-on-error: true # TODO(https://github.com/ooni/probe/issues/2180)
|
||||
uses: securego/gosec@master
|
||||
with:
|
||||
args: ./...
|
||||
|
|
|
|||
Loading…
Reference in a new issue