Skip to content

Add required token permissions to reusable workflow callers - #373

Open
srbouffard wants to merge 3 commits into
mainfrom
update-promote-permissions
Open

Add required token permissions to reusable workflow callers#373
srbouffard wants to merge 3 commits into
mainfrom
update-promote-permissions

Conversation

@srbouffard

Copy link
Copy Markdown
Contributor

Summary

Add explicit GITHUB_TOKEN permissions required by canonical/operator-workflows reusable workflows.

Changes

  • Add missing permissions for publish/promote/comment/bot approval/auto-update workflows
  • Add explicit contents: read for docs workflow callers
  • Scope test workflow permissions for the Allure report job

@srbouffard
srbouffard requested a review from a team as a code owner June 18, 2026 21:49
@srbouffard
srbouffard requested review from florentianayuwono and javierdelapuente and removed request for a team June 18, 2026 21:49
@github-actions

Copy link
Copy Markdown
Contributor

Unused entries in .trivyignore

Image: ghcr.io/canonical/wordpress:8f494ab4a1cdbe62ed8a0ab4c3e7edf220239f0c-_1.0_amd64

The following CVEs are in .trivyignore but not ignored by Trivy anymore:

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

Unused entries in .trivyignore

Image: ghcr.io/canonical/wordpress:8f494ab4a1cdbe62ed8a0ab4c3e7edf220239f0c-_1.0_amd64

The following CVEs are in .trivyignore but not ignored by Trivy anymore:

@github-actions

Copy link
Copy Markdown
Contributor

Unused entries in .trivyignore

Image: ghcr.io/canonical/wordpress:8f494ab4a1cdbe62ed8a0ab4c3e7edf220239f0c-_1.0_amd64

The following CVEs are in .trivyignore but not ignored by Trivy anymore:

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

Unused entries in .trivyignore

Image: ghcr.io/canonical/wordpress:8f494ab4a1cdbe62ed8a0ab4c3e7edf220239f0c-_1.0_amd64

The following CVEs are in .trivyignore but not ignored by Trivy anymore:

@github-actions

Copy link
Copy Markdown
Contributor

Unused entries in .trivyignore

Image: ghcr.io/canonical/wordpress:8f494ab4a1cdbe62ed8a0ab4c3e7edf220239f0c-_1.0_amd64

The following CVEs are in .trivyignore but not ignored by Trivy anymore:

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

Unused entries in .trivyignore

Image: ghcr.io/canonical/wordpress:8f494ab4a1cdbe62ed8a0ab4c3e7edf220239f0c-_1.0_amd64

The following CVEs are in .trivyignore but not ignored by Trivy anymore:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants