From 3e8ea27cc4e200c7e512bd7dd56cd7d95b4a8b4b Mon Sep 17 00:00:00 2001 From: Pulumi Bot Date: Wed, 16 Oct 2024 05:28:16 +0000 Subject: [PATCH] [internal] Update GitHub Actions workflow files --- .github/workflows/master.yml | 2 ++ .github/workflows/prerelease.yml | 2 ++ .github/workflows/publish.yml | 2 +- .github/workflows/release.yml | 3 +++ .github/workflows/run-acceptance-tests.yml | 23 +++++++++++++--------- 5 files changed, 22 insertions(+), 10 deletions(-) diff --git a/.github/workflows/master.yml b/.github/workflows/master.yml index 63b1f8f6ee..df6569daf4 100644 --- a/.github/workflows/master.yml +++ b/.github/workflows/master.yml @@ -98,6 +98,8 @@ jobs: publish: name: publish + permissions: + contents: write needs: - prerequisites - build_provider diff --git a/.github/workflows/prerelease.yml b/.github/workflows/prerelease.yml index ece85bf6f2..c35cf17239 100644 --- a/.github/workflows/prerelease.yml +++ b/.github/workflows/prerelease.yml @@ -61,6 +61,8 @@ jobs: publish: name: publish + permissions: + contents: write needs: - prerequisites - build_provider diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 6326b1b35a..e1597ccdc9 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -108,7 +108,7 @@ jobs: generate_release_notes: true files: dist/* env: - GITHUB_TOKEN: ${{ secrets.PULUMI_BOT_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} publish_sdk: name: publish_sdk diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index bea025669a..1cab1dbee7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -66,6 +66,9 @@ jobs: publish: name: publish + permissions: + contents: write + pull-requests: write needs: - prerequisites - build_provider diff --git a/.github/workflows/run-acceptance-tests.yml b/.github/workflows/run-acceptance-tests.yml index 231fb58373..5fbd92ead4 100644 --- a/.github/workflows/run-acceptance-tests.yml +++ b/.github/workflows/run-acceptance-tests.yml @@ -1,5 +1,15 @@ # WARNING: This file is autogenerated - changes will be overwritten if not made via https://github.com/pulumi/ci-mgmt +name: run-acceptance-tests + +on: + pull_request: + paths-ignore: + - CHANGELOG.md + repository_dispatch: + types: + - run-acceptance-tests-command + env: PR_COMMIT_SHA: ${{ github.event.client_payload.pull_request.head.sha }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -31,6 +41,7 @@ env: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true + jobs: prerequisites: if: github.event_name == 'repository_dispatch' || @@ -62,6 +73,8 @@ jobs: comment-notification: if: github.event_name == 'repository_dispatch' name: comment-notification + permissions: + pull-requests: write runs-on: ubuntu-latest steps: - id: run-url @@ -73,7 +86,7 @@ jobs: body: "Please view the PR build: ${{ steps.run-url.outputs.run-url }}" issue-number: ${{ github.event.client_payload.github.payload.issue.number }} repository: ${{ github.event.client_payload.github.payload.repository.full_name }} - token: ${{ secrets.PULUMI_BOT_TOKEN }} + token: ${{ secrets.GITHUB_TOKEN }} lint: if: github.event_name == 'repository_dispatch' || github.event.pull_request.head.repo.full_name == github.repository @@ -192,11 +205,3 @@ jobs: name: License Check uses: ./.github/workflows/license.yml secrets: inherit -name: run-acceptance-tests -on: - pull_request: - paths-ignore: - - CHANGELOG.md - repository_dispatch: - types: - - run-acceptance-tests-command