Files
my-rook-config/.github/workflows/shellcheck.yaml
T
neilnaveen 2e2eca672a ci: set permissions for github actions
Restrict the GitHub token permissions only to the required ones;
this way, even if the attackers will succeed in compromising your workflow,
they won’t be able to do much.

Included permissions for the action.
https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

Signed-off-by: neilnaveen <42328488+neilnaveen@users.noreply.github.com>
2022-08-04 11:07:00 -06:00

37 lines
776 B
YAML

name: ShellCheck
on:
push:
tags:
- v*
branches:
- master
- release-*
pull_request:
branches:
- master
- release-*
# cancel the in-progress workflow when PR is refreshed.
concurrency:
group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.head_ref || github.sha }}
cancel-in-progress: true
permissions:
contents: read
jobs:
shellcheck:
name: Shellcheck
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v2
- name: Run ShellCheck
uses: ludeeus/action-shellcheck@master
with:
severity: warning
check_together: 'yes'
disable_matcher: false
additional_files: build/reset build/sed-in-place
ignore: olm
format: gcc