Skip to content

Commit 142fda6

Browse files
committed
test
Signed-off-by: ZePan110 <[email protected]>
1 parent a5b074f commit 142fda6

File tree

6 files changed

+91
-8
lines changed

6 files changed

+91
-8
lines changed

.github/workflows/_build_image.yml

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,22 @@
22
# SPDX-License-Identifier: Apache-2.0
33

44
name: Build Images
5-
permissions: read-all
5+
permissions:
6+
actions: read
7+
contents: read
8+
checks: read
9+
deployments: read
10+
discussions: read
11+
issues: read
12+
packages: read
13+
pages: read
14+
pull-requests: read
15+
repository-projects: read
16+
statuses: read
17+
security-events: read
18+
id-token: write
19+
attestations: read
20+
models: read
621
on:
722
workflow_call:
823
inputs:

.github/workflows/_example-workflow.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,21 +3,21 @@
33

44
name: Example jobs
55
permissions:
6-
contents: read
7-
id-token: write
86
actions: read
9-
attestations: read
7+
contents: read
108
checks: read
119
deployments: read
1210
discussions: read
1311
issues: read
14-
models: read
1512
packages: read
1613
pages: read
1714
pull-requests: read
1815
repository-projects: read
1916
statuses: read
2017
security-events: read
18+
id-token: write
19+
attestations: read
20+
models: read
2121
on:
2222
workflow_call:
2323
inputs:

.github/workflows/_get-image-list.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,8 @@
22
# SPDX-License-Identifier: Apache-2.0
33

44
name: Get Image List
5-
permissions: read-all
5+
permissions:
6+
contents: read
67
on:
78
workflow_call:
89
inputs:

.github/workflows/manual-reset-local-registry.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,21 @@
33

44
name: Clean up Local Registry on manual event
55
permissions:
6+
actions: read
67
contents: read
8+
checks: read
9+
deployments: read
10+
discussions: read
11+
issues: read
12+
packages: read
13+
pages: read
14+
pull-requests: read
15+
repository-projects: read
16+
statuses: read
17+
security-events: read
18+
id-token: write
19+
attestations: read
20+
models: read
721
on:
822
workflow_dispatch:
923
inputs:

.github/workflows/nightly-docker-build-publish.yml

Lines changed: 41 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,15 @@
33

44
name: Nightly build/publish latest docker images
55
permissions:
6-
contents: read
6+
security-events: read
7+
78
on:
89
schedule:
910
- cron: "30 14 * * 1-5" # UTC time
1011
workflow_dispatch:
1112

1213
env:
13-
EXAMPLES: ${{ vars.NIGHTLY_RELEASE_EXAMPLES }}
14+
EXAMPLES: "DBQnA" #${{ vars.NIGHTLY_RELEASE_EXAMPLES }}
1415
TAG: "latest"
1516
PUBLISH_TAGS: "latest"
1617

@@ -34,12 +35,32 @@ jobs:
3435
echo "PUBLISH_TAGS=$PUBLISH_TAGS" >> $GITHUB_OUTPUT
3536
3637
build-comps-base:
38+
permissions:
39+
attestations: read
40+
models: read
41+
security-events: read
3742
needs: [get-build-matrix]
3843
uses: ./.github/workflows/_build_comps_base_image.yml
3944
with:
4045
node: gaudi
4146

4247
build-images:
48+
permissions:
49+
actions: read
50+
contents: read
51+
checks: read
52+
deployments: read
53+
discussions: read
54+
issues: read
55+
packages: read
56+
pages: read
57+
pull-requests: read
58+
repository-projects: read
59+
statuses: read
60+
security-events: read
61+
id-token: write
62+
attestations: read
63+
models: read
4364
needs: [get-build-matrix, build-comps-base]
4465
strategy:
4566
matrix:
@@ -54,6 +75,22 @@ jobs:
5475

5576
test-example:
5677
needs: [get-build-matrix]
78+
permissions:
79+
actions: read
80+
contents: read
81+
checks: read
82+
deployments: read
83+
discussions: read
84+
issues: read
85+
packages: read
86+
pages: read
87+
pull-requests: read
88+
repository-projects: read
89+
statuses: read
90+
security-events: read
91+
id-token: write
92+
attestations: read
93+
models: read
5794
if: ${{ needs.get-build-matrix.outputs.examples_json != '' }}
5895
strategy:
5996
matrix:
@@ -70,6 +107,8 @@ jobs:
70107

71108
get-image-list:
72109
needs: [get-build-matrix]
110+
permissions:
111+
contents: read
73112
uses: ./.github/workflows/_get-image-list.yml
74113
with:
75114
examples: ${{ needs.get-build-matrix.outputs.EXAMPLES }}

.github/workflows/push-image-build.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,21 @@
44
name: Build latest images on push event
55

66
permissions:
7+
actions: read
78
contents: read
9+
checks: read
10+
deployments: read
11+
discussions: read
12+
issues: read
13+
packages: read
14+
pages: read
15+
pull-requests: read
16+
repository-projects: read
17+
statuses: read
18+
security-events: read
19+
id-token: write
20+
attestations: read
21+
models: read
822

923
on:
1024
push:

0 commit comments

Comments
 (0)