Add explicit permissions to GitHub Actions#24579
Conversation
Also update the CircleCI check to the action's latest recommended jobs.
67334d7 to
feec9c5
Compare
|
I threw in a few bugs, and they were correctly reported, so I've removed them now. Not 100% confident on the nightly bits, as the GitHub docs are a bit vague on what the permissions do, but I think they're correct. |
|
Owee, I'm MrMeeseeks, Look at me. There seem to be a conflict, please backport manually. Here are approximate instructions:
And apply the correct labels and milestones. Congratulations — you did some good work! Hopefully your backport PR will be tested by the continuous integration and merged soon! Remember to remove the If these instructions are inaccurate, feel free to suggest an improvement. |
Merge pull request matplotlib#24579 from QuLogic/action-permissions Add explicit permissions to GitHub Actions (cherry picked from commit 24f9128)
…-v3.6.x Backport PR #24579: Add explicit permissions to GitHub Actions
PR Summary
While everything we do is basically public, there's no reason to give the tokens on these jobs full permissions. (Note, once a single item is added, all other permissions are disabled.)
Also update the CircleCI check to the action's latest recommended jobs.
PR Checklist
Documentation and Tests
pytestpasses)Release Notes
.. versionadded::directive in the docstring and documented indoc/users/next_whats_new/.. versionchanged::directive in the docstring and documented indoc/api/next_api_changes/next_whats_new/README.rstornext_api_changes/README.rst