File tree Expand file tree Collapse file tree 3 files changed +33
-0
lines changed Expand file tree Collapse file tree 3 files changed +33
-0
lines changed Original file line number Diff line number Diff line change 1+ version : ' minty.abcxyz.dev/v2'
2+
3+ rule :
4+ if : |-
5+ assertion.iss == 'https://token.actions.githubusercontent.com' &&
6+ assertion.organization_id == '93787867' &&
7+ assertion.repository_id == '560465650' &&
8+ assertion.ref == 'refs/heads/main'
9+
10+ scope :
11+ update-checksums :
12+ rule :
13+ if : |-
14+ assertion.workflow_ref.startsWith("abcxyz/secure-setup-terraform/.github/workflows/update-checksums.yml") &&
15+ (assertion.event_name == 'schedule' || assertion.event_name == 'workflow_dispatch')
16+ repositories :
17+ - ' secure-setup-terraform'
18+ permissions :
19+ pull_requests : ' write'
20+ contents : ' write'
21+
22+ create-release :
23+ rule :
24+ if : |-
25+ assertion.workflow_ref.startsWith("abcxyz/secure-setup-terraform/.github/workflows/create-release.yml") &&
26+ assertion.event_name == 'push'
27+ repositories :
28+ - ' secure-setup-terraform'
29+ permissions :
30+ contents : ' write'
31+
Original file line number Diff line number Diff line change 6060 service_url : ' ${{ vars.TOKEN_MINTER_SERVICE_URL }}'
6161 requested_permissions : |-
6262 {
63+ "scope": "create-release",
6364 "repositories": ["${{ github.event.repository.name }}"],
6465 "permissions": {
6566 "contents": "write"
Original file line number Diff line number Diff line change 4848 service_url : ' ${{ vars.TOKEN_MINTER_SERVICE_URL }}'
4949 requested_permissions : |-
5050 {
51+ "scope": "update-checksums",
5152 "repositories": ["secure-setup-terraform"],
5253 "permissions": {
5354 "pull_requests": "write",
You can’t perform that action at this time.
0 commit comments