Merge branch 'main' into dependabot/npm_and_yarn/npm-development-d185e289e1

This commit is contained in:
Brian DeHamer 2024-04-22 09:13:06 -07:00 committed by GitHub
commit cbd145074f
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 8 additions and 5 deletions

View File

@ -50,7 +50,8 @@ jobs:
name: Test attest-provenance action
runs-on: ubuntu-latest
permissions:
contents: write
attestations: write
contents: read
id-token: write
steps:

View File

@ -29,11 +29,11 @@ attest:
```yaml
permissions:
id-token: write
contents: write # TODO: Update this
attestations: write
```
The `id-token` permission gives the action the ability to mint the OIDC token
permission is necessary to persist the attestation. The `contents` permission
permission is necessary to persist the attestation. The `attestations` permission
is necessary to persist the attestation.
1. Add the following to your workflow after your artifact has been built:
@ -112,7 +112,8 @@ jobs:
build:
permissions:
id-token: write
contents: write
contents: read
attestations: write
steps:
- name: Checkout
@ -166,7 +167,8 @@ jobs:
permissions:
id-token: write
packages: write
contents: write
contents: read
attestations: write
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}